N/A
2026-03-11< 2.8.7
My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action
Minimum safe version
2.8.7
Update to 2.8.7 or later to address 7 fixable vulnerabilities
My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action
CVE-2024-7133
CVE-2024-4090
WordPress My Sticky Bar Plugin < 2.6.8 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-7048
CVE-2023-5509
CVE-2021-24425