Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation allows malicious script code to be stored by the PSM Plugins SupportCandy plugin. When a user views the affected page, the injected script executes in the browser, enabling a range of defacement or manipulation of page content.

Affected Systems

The vulnerability affects all released versions of the PSM Plugins SupportCandy WordPress plugin up to and including version 3.4.8. Users running any of these versions are susceptible unless the plugin has been removed or otherwise mitigated.

Risk and Exploitability

The CVSS score of 6.5 signals moderate severity, while the EPSS score of less than 1% indicates that exploitation is currently considered rare. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply malicious input that is stored by the plugin and later rendered to a user’s browser; no higher privileges or additional conditions are documented in the CVE description.

Generated by OpenCVE AI on July 29, 2026 at 07:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove or disable the SupportCandy plugin to prevent malicious code from being stored.
  • Deploy a web application firewall or configure request filtering to block malicious input before it reaches the plugin.
  • Apply a strict Content Security Policy that disallows inline scripts and restricts script sources, mitigating the impact of any stored XSS that may remain.

Generated by OpenCVE AI on July 29, 2026 at 07:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Psm Plugins
Psm Plugins supportcandy
Wordpress
Wordpress wordpress
Vendors & Products Psm Plugins
Psm Plugins supportcandy
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.
Title WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Psm Plugins Supportcandy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T16:07:50.905Z

Reserved: 2026-06-25T08:04:04.790Z

Link: CVE-2026-57711

cve-icon Vulnrichment

Updated: 2026-07-13T16:02:08.807Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T08:00:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')