Extension WordPress
Vulnérabilités SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
Cette page rassemble les failles publiées pour SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent
19 fiches
SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent <= 3.4.8 – Authenticated (Customer+) Stored Cross-Site Scripting
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes…
*-3.4.8
3.4.9
10/07/2026
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.6 – Authenticated (Subscriber+) Insecure Direct Object Reference
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.6 due to missing validation on a user controlled key. This makes…
*-3.4.6
3.4.7
17/06/2026
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Authenticated (Subscriber+) SQL Injection via Number Field Filter
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field filter in all versions up to, and including, 3.4.4. This is due to insufficient escaping on…
*-3.4.4
3.4.5
30/01/2026
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Missing Authorization
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 3.4.4. This makes it possible…
*-3.4.4
3.4.5
29/01/2026
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 – Authenticated (Subscriber+) Insecure Direct Object Reference
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.4 via the 'add_reply' function due to missing validation on a user…
*-3.4.4
3.4.5
23/01/2026
SupportCandy <= 3.4.1 – Cross-Site Request Forgery
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.4.1. This is due to missing or incorrect nonce validation on a function.…
*-3.4.1
3.4.2
21/11/2025
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 – Authentication Bypass to Support Session Takeover
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest…
*-3.3.7
3.3.8
19/09/2025
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 – Insecure Direct Object Reference
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.0 via file upload due to missing validation on a user controlled…
*-3.3.0
3.3.1
06/03/2025
SupportCandy <= 3.2.3 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The SupportCandy plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-3.2.3
3.2.4
15/03/2024
SupportCandy <= 3.1.6 – Authenticated (Subscriber+) SQL Injection
The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'id' parameter used in the /wp-json/supportcandy/v2/agents/ REST route in versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack…
*-3.1.6
3.1.7
22/05/2023
SupportCandy <= 3.1.6 – Authenticated (Admin+) SQL Injection
The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'agents[]' parameter used in the set_add_agent_leaves AJAX action in versions up to, and including, 3.1.6 due to insufficient escaping on the user supplied parameter and lack…
*-3.1.6
3.1.7
22/05/2023
SupportCandy <= 3.1.4 – Unauthenticated SQL Injection via parse_user_filters
The SupportCandy plugin for WordPress is vulnerable to SQL injection via the 'parse_user_filters' function in versions up to, and including, 3.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…
*-3.1.4
3.1.5
10/04/2023
SupportCandy <= 3.1.3 – Sensitive Data Exposure
The SupportCandy plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.1.3. Users seeking support have the option to upload supporting documents which are placed in /wp-content/uploads/wpsc/. If directory listing is enabled,…
*-3.1.3
3.1.4
28/03/2023
SupportCandy <= 2.2.4 – Unauthenticated Arbitrary Ticket Deletion
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be…
*-2.2.4
2.2.5
05/01/2022
SupportCandy <= 2.2.6 – Reflected Cross-Site Scripting
The SupportCandy WordPress plugin before 2.2.7 does not sanitise and escape the query string before outputting it back in pages with the [wpsc_create_ticket] shortcode embed, leading to a Reflected Cross-Site Scripting issue
*-2.2.6
2.2.7
05/01/2022
SupportCandy – Helpdesk & Support Ticket System <= 2.2.6 – Cross-Site Request Forgery to Stored Cross-Site Scripting
The SupportCandy – Helpdesk & Support Ticket System WordPress plugin before 2.2.7 does not have CSRF check in the wpsc_tickets AJAX action, nor has any sanitisation or escaping in some of the filter fields which could allow attackers…
[*, 2.2.7)
2.2.7
05/01/2022
SupportCandy <= 2.2.6 – Stored Cross-Site Scripting via Shortcode
The SupportCandy WordPress plugin before 2.2.7 does not validate and escape the page attribute of its shortcode, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
[*, 2.2.7)
2.2.7
04/01/2022
SupportCandy <= 2.2.6 – Cross-Site Request Forgery to Arbitrary Ticket Deletion
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.
[*, 2.2.7)
2.2.7
04/01/2022
SupportCandy – Helpdesk & Support Ticket System <= 2.0.0 – Arbitrary File Upload
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
[*, 2.0.1)
2.0.1
17/04/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.