rootpwn

medium · CVSS v3 6.4

CVE-2026-94378

SupportCandy plugin for WordPress allows stored XSS via the 'name' field in all versions up to 3.5.3. Authenticated users with subscriber or

Overview

SupportCandy plugin for WordPress allows stored XSS via the 'name' field in all versions up to 3.5.3. Authenticated users with subscriber or higher roles can inject scripts that run for any user viewing the affected page. The flaw requires the default 'Register user if not exists' setting to be disabled.

Description

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This exploit chain requires the 'Register user if not exists' setting to be disabled, which is its default configuration.

Impact

Confidentiality: attackers can steal session cookies or other sensitive data. Integrity: malicious scripts can modify page content. Availability: repeated XSS can degrade user experience. Defenders must monitor for injected scripts and restrict subscriber-level access.

Remediation

Upgrade SupportCandy to version 3.5.4 or later. If an upgrade is not possible, disable the plugin or enable the 'Register user if not exists' setting. Additionally, enforce strict role permissions, block the 'name' parameter via a WAF, and sanitize user input on the server side.

Risk context

Medium severity (CVSS 6.4). No EPSS data available. The vulnerability is exploitable by any authenticated subscriber, making it a moderate risk that should be addressed promptly.

Affected products

  • SupportCandy WordPress plugin

Scores

Severity
medium
CVSS v2
5.5
CVSS v3
6.4
CVSS v4
—
EPSS
—

wordpress plugin xss stored authentication defense

← All CVEs