WordPress Plugin All-in-one Floating Contact Form Call Chat and 50 Social Icon Tabs-My Sticky Elements SQL Injection - CVE-2023-0487 - Vulnerability Database

WordPress Plugin All-in-one Floating Contact Form Call Chat and 50 Social Icon Tabs-My Sticky Elements SQL Injection - CVE-2023-0487

High
Reference: CVE-2023-0487
Title: WordPress Plugin All-in-one Floating Contact Form Call Chat and 50 Social Icon Tabs-My Sticky Elements SQL Injection
Overview:

WordPress Plugin All-in-one Floating Contact Form Call Chat and 50 Social Icon Tabs-My Sticky Elements is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query. Exploiting this issue could allow an attacker to compromise the application access or modify data or exploit latent vulnerabilities in the underlying database. WordPress Plugin All-in-one Floating Contact Form Call Chat and 50 Social Icon Tabs-My Sticky Elements version 2.0.8 is vulnerable prior versions may also be affected.