Skip to content
MediumVulnerability

CVE-2026-94539: SupportCandy plugin time-based SQL injection via sort_by parameter

Identifier
CVE-2026-94539
Published
Record updated
View JSON
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The SupportCandy AI Customer Support Ticket System and Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL injection through the 'sort_by' parameter in all versions up to and including 3.5.3. The flaw stems from insufficient escaping of user-supplied input and a SQL query that is not sufficiently prepared. An authenticated attacker can append SQL queries to existing ones and extract sensitive information from the database. Exploitation requires a Subscriber-level or higher WordPress role and a SupportCandy Agent account with the 'Assign Agents' permission.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.