A vulnerability was found in Chaty Pro Plugin up to 3.5.5 on WordPress and classified as critical. Affected is the function
fetch_custom_field of the file admin/class-admin-base.php. Executing a manipulation of the argument widget_id can lead to sql injection.
This vulnerability is registered as CVE-2026-6251. It is possible to launch the attack remotely. No exploit is available.