What happened
NVD published CVE-2026-94539 (CVSS 6.5) on 2026-10-03 for a time-based SQL injection (inadequate escaping of the sort_by parameter) in all versions of the SupportCandy AI chatbot ticket plugin up to and including 3.5.3.
Why it matters
The plugin is an AI-powered customer support chatbot that stores ticket data and user records; SQLi here can dump the WordPress database behind an AI chatbot surface. Narrow (single plugin) but real for websites that deploy this AI support ticket system.
Attack vector
Time-based blind SQL injection via the unsanitized 'sort_by' parameter in list endpoints; an attacker can extract data from the WordPress database (users, hashes, tickets) through timing side channels.
Affected systems
SupportCandy AI Customer Support Ticket System & Live Chatbot Agent WordPress plugin <= 3.5.3
Mitigation
Update the SupportCandy plugin to a version newer than 3.5.3 once the vendor releases a fix. Reference: https://plugins.svn.wordpress.org/supportcandy/