My Sticky Bar (formerly myStickymenu) is a plugin for WordPress that adds features such as a Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header. Unfortunately, all versions up to and including 2.6.4 are vulnerable to unauthorized modification of data. This means that if someone with subscriber-level access or above is able to gain access to the system, they can delete form leads without permission. Additionally, there are several AJAX actions in the plugin with missing capability checks, such as mystickymenu_admin_send_message_to_owner(), stickymenu_widget_delete(), mystickymenu_widget_status(), which can also be used to perform unauthorized actions.