Impact
The vulnerability is a stored cross‑site scripting flaw that exists in the 'name' parameter of the SupportCandy plugin up to version 3.5.3. Because the plugin does not properly escape or sanitize user‑supplied data before storing it in the database and later rendering it in web pages, an attacker can inject arbitrary JavaScript or other web scripts. When a victim loads a page containing the injected content the script executes in the victim’s browser under the site’s domain, potentially enabling session hijacking, credential theft, or defacement. The weakness is a classic Reflected/Stored XSS represented by CWE‑79.
Affected Systems
The affected product is the SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plug‑in for WordPress, versions 3.5.3 and earlier. All WordPress sites running this plug‑in without an upgrade to a patched release (starting at 3.5.4 or newer) are vulnerable, provided the plug‑in’s 'Register user if not exists' setting remains in its default disabled state.
Risk and Exploitability
The CVSS score of 6.4 reflects a moderate to high severity for XSS that requires authenticated access only to subscriber‐level or higher roles. The EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not catalogued in CISA KEV, implying no confirmed exploitation in the wild yet. Attackers would need to log in with sufficient privileges to create or modify a customer agent or customer record, then use the vulnerable 'name' field. The exploit requires no special network conditions and executes entirely within the host’s web application once the payload is rendered.
OpenCVE Enrichment