Description
The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data extraction via SQL injection
Action: Immediate Patch
AI Analysis

Impact

The Sticky Chat Widget plugin for WordPress contains an unauthenticated SQL injection vulnerability in the scw_save_form_data AJAX action. Attacker‑controlled keys in the scw_form_fields POST array are inserted directly into a SQL query without proper escaping, enabling the injection of arbitrary SQL. This flaw allows an unauthenticated user to execute malicious statements that can read or modify the database, potentially exposing sensitive site data.

Affected Systems

The vulnerability affects the Gingerplugins Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email Any site using version 1.4.2 or earlier is susceptible until the plugin is updated to a version that sanitizes input.

Risk and Exploitability

The flaw carries a CVSS score of 7.5. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires no authentication and only a crafted AJAX request to the scw_save_form_data endpoint, exploitation is straightforward for an attacker with network access to the site. Successful exploitation can lead to data exfiltration or unauthorized database manipulation.

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Sticky Chat Widget to a fixed version (any released version after 1.4.2).
  • If upgrade is not immediately possible, disable the scw_save_form_data AJAX action for non‑admin users by adding a capability check or removing the action via code.
  • After applying changes, review database logs for suspicious activity and enforce least privilege access on your database user account used by WordPress.

Generated by OpenCVE AI on September 11, 2026 at 05:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Gingerplugins
Gingerplugins sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click To Chat, Email & Message Buttons
Wordpress
Wordpress wordpress
Vendors & Products Gingerplugins
Gingerplugins sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click To Chat, Email & Message Buttons
Wordpress
Wordpress wordpress

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled POST array keys unsanitized to $wpdb->insert(), which wraps column identifiers in backticks without escaping them, allowing a backtick in an attacker-supplied key to break out of the column-identifier list into raw SQL; additionally, the use of filter_input() bypasses WordPress's wp_magic_quotes() protection, and the widget_id validation loop is skipped entirely when no valid widget_id is supplied, leaving $isValid at 1. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Title Sticky Chat Widget <= 1.4.2 - Unauthenticated SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Gingerplugins Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click To Chat, Email & Message Buttons
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T14:12:05.799Z

Reserved: 2026-07-10T20:14:05.080Z

Link: CVE-2026-15462

cve-icon Vulnrichment

Updated: 2026-09-11T14:11:57.420Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T04:17:20.173

Modified: 2026-09-11T15:16:59.660

Link: CVE-2026-15462

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T19:57:12Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')