Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 13 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gingerplugins
Gingerplugins sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click To Chat, Email & Message Buttons Wordpress Wordpress wordpress |
|
| Vendors & Products |
Gingerplugins
Gingerplugins sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click To Chat, Email & Message Buttons Wordpress Wordpress wordpress |
Fri, 11 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 11 Sep 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | |
| Title | Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-09-11T14:12:05.799Z
Reserved: 2026-07-10T20:14:05.080Z
Link: CVE-2026-15462
Updated: 2026-09-11T14:11:57.420Z
Status : Deferred
Published: 2026-09-11T04:17:20.173
Modified: 2026-09-11T15:16:59.660
Link: CVE-2026-15462
No data.
OpenCVE Enrichment
Updated: 2026-09-13T19:57:12Z