CVE-2026-73187: WordPress Sticky Chat Widget plugin <= 1.4.2 - SQL Injection vulnerability
Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Sticky Chat Widget Pluginto a version that resolves this vulnerability.Fixed in 1.4.3
Event History
Frequently Asked Questions
Which installations are affected?
Sites using Sticky Chat Widget version 1.4.2 or earlier are affected. The issue is in a WordPress plugin rather than WordPress itself.
What does an attacker need to exploit this?
An attacker does not need authentication or user interaction. The network-accessible, low-complexity attack vector indicates exploitation can be attempted remotely against an exposed site.
Is there a documented fixed version or temporary mitigation?
The provided data identifies affected versions through 1.4.2 but does not provide a fixed version or mitigation. If patching cannot be performed immediately, no supported workaround is specified in the available information.