{"data":{"id":"95cf1aaa-33f1-40d1-b29b-39a769dd3f1b","title":"CVE-2026-94378: The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored…","summary":"CVE-2026-94378 affects the SupportCandy AI Customer Support Ticket System and Live Chatbot Agent plugin for WordPress in all versions up to and including 3.5.3. The 'name' parameter lacks sufficient input sanitization and output escaping, enabling Stored Cross-Site Scripting. An authenticated attacker with subscriber-level access or above can inject web scripts that execute whenever a user views an injected page. The exploit chain requires the 'Register user if not exists' setting to be disabled, which is its default configuration.","solution":"N/A -- no mitigation discussed in source.","labels":["security","industry"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-94378","publishedAt":"2026-10-03T03:16:37.230Z","cveId":"CVE-2026-94378","cweIds":["CWE-79"],"cvssScore":"6.4","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["SupportCandy","SupportCandy AI Customer Support Ticket System","SupportCandy Live Chatbot Agent"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":"SupportCandy WordPress plugin stored cross-site scripting via name parameter","headlinePromptVersion":"h1","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00201,"epssCheckedAt":"2026-10-10T06:42:02.840Z","kevDateAdded":null,"advisoryAliases":["GHSA-8cxj-g538-75wh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":"2026-10-10T03:43:00.581Z","patchAvailable":null,"disclosureDate":"2026-10-03T03:16:37.230Z","capecIds":["CAPEC-198","CAPEC-86"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"plugin","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}