---
id: CVE-2026-4661
title: >-
  The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for
  WordPress is vulnerable to time-based blind SQL Injection via the 'fildname'
  parameter in all versions up to, and including, 2.2.2
summary: >-
  The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for
  WordPress is vulnerable to time-based blind SQL Injection via the 'fildname'
  parameter in all versions up to, and including, 2.2.2. This is due to
  insufficient esc…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-89
published: '2026-07-11'
updated: '2026-07-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-4661'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L17
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L186
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/easy-sticky-sidebar/tags/1.7.4/inc/ClassActions.php#L193
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3524743%40easy-sticky-sidebar&new=3524743%40easy-sticky-sidebar
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/7e963601-dc41-4218-9119-708c74e51bc2?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00505
epssPercentile: 0.4052
ingestedAt: '2026-07-11T23:16:20.866Z'
---

## Overview

The WP CTA – Sticky CTA Builder, Generate Leads, Promote Sales plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'fildname' parameter in all versions up to, and including, 2.2.2. This is due to insufficient escaping of user-supplied column names in the ajaxCheck() method and lack of preparation in the $wpdb->update() call. The vulnerability is compounded by the complete absence of authorization checks and the endpoint being registered for unauthenticated users via wp_ajax_nopriv_. This makes it possible for unauthenticated attackers to inject arbitrary SQL queries and extract sensitive information from the database via time-based blind SQL injection techniques, including administrator password hashes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
