PatchSiren

gingerplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH gingerplugins CVE published 2026-09-11

CVE-2026-15462

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This vulnerability allows unauthenticated attackers to inject malicious SQL queries, potentially leading to data breaches or other security incidents. WordPress administrators and defenders should assess t [truncated]