Description
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This exploit chain requires the 'Register user if not exists' setting to be disabled, which is its default configuration.
Published: 2026-10-03
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a stored cross‑site scripting flaw that exists in the 'name' parameter of the SupportCandy plugin up to version 3.5.3. Because the plugin does not properly escape or sanitize user‑supplied data before storing it in the database and later rendering it in web pages, an attacker can inject arbitrary JavaScript or other web scripts. When a victim loads a page containing the injected content the script executes in the victim’s browser under the site’s domain, potentially enabling session hijacking, credential theft, or defacement. The weakness is a classic Reflected/Stored XSS represented by CWE‑79.

Affected Systems

The affected product is the SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plug‑in for WordPress, versions 3.5.3 and earlier. All WordPress sites running this plug‑in without an upgrade to a patched release (starting at 3.5.4 or newer) are vulnerable, provided the plug‑in’s 'Register user if not exists' setting remains in its default disabled state.

Risk and Exploitability

The CVSS score of 6.4 reflects a moderate to high severity for XSS that requires authenticated access only to subscriber‐level or higher roles. The EPSS score is not available, so the likelihood of exploitation is uncertain. The vulnerability is not catalogued in CISA KEV, implying no confirmed exploitation in the wild yet. Attackers would need to log in with sufficient privileges to create or modify a customer agent or customer record, then use the vulnerable 'name' field. The exploit requires no special network conditions and executes entirely within the host’s web application once the payload is rendered.

Generated by OpenCVE AI on October 3, 2026 at 03:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SupportCandy plug‑in to the latest available version (3.5.4 or newer).
  • If an upgrade cannot be performed immediately, restrict submission of the ‘name’ field to trusted roles or implement server‑side filtering to strip script tags and JavaScript before storage.
  • Monitor site activity for suspicious entries in customer and agent records and review logs for recent changes to the 'name' field.

Generated by OpenCVE AI on October 3, 2026 at 03:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This exploit chain requires the 'Register user if not exists' setting to be disabled, which is its default configuration.
Title SupportCandy <= 3.5.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'name' Parameter
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.299Z

Reserved: 2026-09-21T12:34:10.300Z

Link: CVE-2026-94378

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:49.204Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:37.230

Modified: 2026-10-03T16:16:45.133

Link: CVE-2026-94378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T03:30:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')