What is CVE-2026-6251?
The Chaty Pro plugin for WordPress (up to version 3.5.5) contains an authenticated Time-Based Blind SQL Injection vulnerability. This is due to insufficient sanitization of the `widget_id` POST parameter in the `fetch_custom_field()` function within `admin/class-admin-base.php`. Users should immediately update to the latest version or temporarily disable the plugin.
Azərbaycanca: Chaty Pro WordPress plaqini (3.5.5-ə qədər versiyalar) autentifikasiya olunmuş Time-Based Blind SQL Injection zəifliyinə məruz qalır. Bu zəiflik `admin/class-admin-base.php` faylındakı `fetch_custom_field()` funksiyasında `widget_id` POST parametrinin düzgün təmizlənməməsindən qaynaqlanır. İstifadəçilər plaqini dərhal ən son versiyaya yeniləməli və ya müvəqqəti olaraq deaktiv etməlidirlər.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
Does exploiting the SQL Injection vulnerability CVE-2026-6251 in the Chaty Pro plugin require authentication?
Yes, CVE-2026-6251 is an authenticated Time-Based Blind SQL Injection vulnerability, meaning a logged-in user account is required to perform the attack.
In which file of the Chaty Pro plugin does the CVE-2026-6251 vulnerability exist?
The vulnerability exists in the `fetch_custom_field()` function within the `admin/class-admin-base.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.