CVE-2022-3858: Chaty < 3.0.3 - Admin+ SQLi
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line, WeChat, Email, SMS, Call Button WordPress plugin before 3.0.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-3858?
CVE-2022-3858 is a vulnerability in the Floating Chat Widget: Contact Chat Icons WordPress plugin before version 3.0.3 that allows SQL injection.
How severe is CVE-2022-3858?
CVE-2022-3858 has a severity score of 7.2 (high).
Which software versions are affected by CVE-2022-3858?
The Floating Chat Widget: Contact Chat Icons plugin versions before 3.0.3 are affected by CVE-2022-3858.
How can I fix CVE-2022-3858?
To fix CVE-2022-3858, update the Floating Chat Widget: Contact Chat Icons plugin to version 3.0.3 or higher.
What is the Common Weakness Enumeration (CWE) of CVE-2022-3858?
The Common Weakness Enumeration (CWE) of CVE-2022-3858 is CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).