The plugin does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
id: CVE-2024-5765
info:
name: WpStickyBar <= 2.1.0 - SQL Injection
author: theamanrawat
sever
...