Impact
The SupportCandy WordPress plugin exposes a time‑based SQL Injection vulnerability in the "sort_by" request parameter. Unsanitized user input combined with a missing query parameterization allows an attacker with authenticated access to concatenate additional SQL statements. This can result in the extraction of sensitive database information. The flaw is limited to attackers who possess at least a Subscriber‑level WordPress role and a SupportCandy Agent account that holds the "Assign Agents" permission.
Affected Systems
All releases of the SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress up to and including version 3.5.3 are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user who is both an authenticated WordPress subscriber or higher and a SupportCandy Agent with "Assign Agents" privilege, which reduces the attack surface but still allows data theft once the conditions are met. The attack vector relies on a direct, time‑based injection via an authenticated user interaction with the "sort_by" parameter.
OpenCVE Enrichment