Impact
The Sticky Chat Widget plugin for WordPress contains an unauthenticated SQL injection vulnerability in the scw_save_form_data AJAX action. Attacker‑controlled keys in the scw_form_fields POST array are inserted directly into a SQL query without proper escaping, enabling the injection of arbitrary SQL. This flaw allows an unauthenticated user to execute malicious statements that can read or modify the database, potentially exposing sensitive site data.
Affected Systems
The vulnerability affects the Gingerplugins Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email Any site using version 1.4.2 or earlier is susceptible until the plugin is updated to a version that sanitizes input.
Risk and Exploitability
The flaw carries a CVSS score of 7.5. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires no authentication and only a crafted AJAX request to the scw_save_form_data endpoint, exploitation is straightforward for an attacker with network access to the site. Successful exploitation can lead to data exfiltration or unauthorized database manipulation.
OpenCVE Enrichment