SQL Injection Vulnerability in SupportCandy Ticket System Plugin for WordPress
CVE-2026-94539
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 October 2026
What is CVE-2026-94539?
The SupportCandy plugin for WordPress presents a security risk due to a vulnerability that permits time-based SQL injection through the 'sort_by' parameter. This affects all versions up to and including 3.5.3, where insufficient escaping of user-supplied input allows authenticated attackers with a Subscriber-level or higher WordPress role to manipulate SQL queries. By appending malicious SQL code, attackers can access sensitive database information, posing a significant danger to the integrity of user data and system security.
Affected Version(s)
SupportCandy β AI Customer Support Ticket System & Live Chatbot Agent 0 <= 3.5.3