← WordPress Vulnerabilities
WordPress security by component

Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button

Sticky Chat Widget adds a customizable website contact widget with links for chat, SMS, email, messaging services, phone calls, and live support.

Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button (sticky-chat-widget) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 9.3.

Plugin slug: sticky-chat-widget

CVE-2026-15462: Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons: SQL injection

Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.4.2.

PublishedSep 11, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for sticky-chat-widget
Safe version
Sep 11, 2026 CVE-2026-15462
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons: SQL injection
Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message Buttons is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is <= 1.4.2.
See mitigation notes
CVE7.5
NVDPending
Aug 18, 2026 CVE-2026-73187
Sticky Chat Widget: SQL injection
Sticky Chat Widget is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 1.4.2.
1.4.3
CVE9.3
NVDPending
Dec 29, 2023 CVE-2023-51361
Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button: Cross-site scripting
Sticky Chat Widget: Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.9
NVD4.8