Extension WordPress

Vulnérabilités SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

Cette page rassemble les failles publiées pour SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent, leurs plages de versions affectées et les correctifs signalés dans la base locale.

19Vulnérabilités
2Critiques
19Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

19 fiches

CVE-2026-57711 Moyenne · 6,4
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 – Authenticated (Customer+) Stored Cross-Site Scripting

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-3.4.8

Correctif

3.4.9

Publication

10/07/2026

CVE-2026-54826 Moyenne · 4,3
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.6 – Authenticated (Subscriber+) Insecure Direct Object Reference

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.6 due to missing validation on a user controlled key. This makes…

Versions affectées

*-3.4.6

Correctif

3.4.7

Publication

17/06/2026

CVE-2026-0683 Moyenne · 6,5
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Authenticated (Subscriber+) SQL Injection via Number Field Filter

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field filter in all versions up to, and including, 3.4.4. This is due to insufficient escaping on…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

30/01/2026

CVE-2026-25321 Moyenne · 5,3
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Missing Authorization

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.4. This makes it possible…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

29/01/2026

CVE-2026-1251 Moyenne · 5,4
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Authenticated (Subscriber+) Insecure Direct Object Reference

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 via the 'add_reply' function due to missing validation on a user…

Versions affectées

*-3.4.4

Correctif

3.4.5

Publication

23/01/2026

CVE-2025-10658 Moyenne · 6,5
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 – Authentication Bypass to Support Session Takeover

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest…

Versions affectées

*-3.3.7

Correctif

3.3.8

Publication

19/09/2025

CVE-2024-13552 Moyenne · 4,3
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 – Insecure Direct Object Reference

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled…

Versions affectées

*-3.3.0

Correctif

3.3.1

Publication

06/03/2025

CVE-2024-27991 Moyenne · 6,4
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 3.2.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting

The SupportCandy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Versions affectées

*-3.2.3

Correctif

3.2.4

Publication

15/03/2024

CVE-2023-2719 Élevée · 8,8
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 3.1.6 – Authenticated (Subscriber+) SQL Injection

The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'id' parameter used in the /wp-json/supportcandy/v2/agents/ REST route in versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-3.1.6

Correctif

3.1.7

Publication

22/05/2023

CVE-2023-2805 Élevée · 7,2
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 3.1.6 – Authenticated (Admin+) SQL Injection

The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'agents[]' parameter used in the set_add_agent_leaves AJAX action in versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack…

Versions affectées

*-3.1.6

Correctif

3.1.7

Publication

22/05/2023

CVE-2023-1730 Critique · 9,8
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 3.1.4 – Unauthenticated SQL Injection via parse_user_filters

The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

Versions affectées

*-3.1.4

Correctif

3.1.5

Publication

10/04/2023

Vulnérabilité Moyenne · 6,5
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 3.1.3 – Sensitive Data Exposure

The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.1.3. Users seeking support have the option to upload supporting documents which are placed in /wp-content/uploads/wpsc/. If directory listing is enabled,…

Versions affectées

*-3.1.3

Correctif

3.1.4

Publication

28/03/2023

CVE-2021-24839 Élevée · 7,5
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 2.2.4 – Unauthenticated Arbitrary Ticket Deletion

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be…

Versions affectées

*-2.2.4

Correctif

2.2.5

Publication

05/01/2022

CVE-2021-24879 Moyenne · 6,1
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy – Helpdesk & Support Ticket System <= 2.2.6 – Cross-Site Request Forgery to Stored Cross-Site Scripting

The SupportCandy – Helpdesk & Support Ticket System WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers…

Versions affectées

[*, 2.2.7)

Correctif

2.2.7

Publication

05/01/2022

CVE-2021-24843 Moyenne · 6,5
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent

SupportCandy <= 2.2.6 – Cross-Site Request Forgery to Arbitrary Ticket Deletion

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.

Versions affectées

[*, 2.2.7)

Correctif

2.2.7

Publication

04/01/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités