Description
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the authenticated attacker to hold both a Subscriber-level (or higher) WordPress role and a SupportCandy Agent account with the 'Assign Agents' permission configured.
Published: 2026-10-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exfiltration via SQL Injection
Action: Patch Immediately
AI Analysis

Impact

The SupportCandy WordPress plugin exposes a time‑based SQL Injection vulnerability in the "sort_by" request parameter. Unsanitized user input combined with a missing query parameterization allows an attacker with authenticated access to concatenate additional SQL statements. This can result in the extraction of sensitive database information. The flaw is limited to attackers who possess at least a Subscriber‑level WordPress role and a SupportCandy Agent account that holds the "Assign Agents" permission.

Affected Systems

All releases of the SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress up to and including version 3.5.3 are affected.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user who is both an authenticated WordPress subscriber or higher and a SupportCandy Agent with "Assign Agents" privilege, which reduces the attack surface but still allows data theft once the conditions are met. The attack vector relies on a direct, time‑based injection via an authenticated user interaction with the "sort_by" parameter.

Generated by OpenCVE AI on October 3, 2026 at 03:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SupportCandy plugin to the latest release that implements proper input sanitization and query parameterization.
  • Restrict the "Assign Agents" capability to only essential staff and audit user roles to prevent unnecessary elevated privileges.
  • If an update is unavailable, apply a temporary code patch that validates or escapes the "sort_by" parameter before it is used in any SQL query, or disable the feature altogether.

Generated by OpenCVE AI on October 3, 2026 at 03:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 02:45:00 +0000

Type Values Removed Values Added
Description The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the authenticated attacker to hold both a Subscriber-level (or higher) WordPress role and a SupportCandy Agent account with the 'Assign Agents' permission configured.
Title SupportCandy <= 3.5.3 - Authenticated (Custom+) SQL Injection via 'sort_by' Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:47.170Z

Reserved: 2026-09-21T18:29:41.510Z

Link: CVE-2026-94539

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:47.715Z

cve-icon NVD

Status : Received

Published: 2026-10-03T03:16:37.383

Modified: 2026-10-03T16:16:45.467

Link: CVE-2026-94539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T03:30:19Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')