Vulnerability  ·  2026-10-05

SupportCandy AI support ticket chatbot: time-based SQL injection via sort_by parameter

VulnerabilityMedium impactGlobalCVE-2026-94539
NVD published CVE-2026-94539 (CVSS 6.5) on 2026-10-03 for a time-based SQL injection (inadequate escaping of the sort_by parameter) in all versions of the SupportCandy AI chatbot ticket plugin up to and including 3.5.3.
The plugin is an AI-powered customer support chatbot that stores ticket data and user records; SQLi here can dump the WordPress database behind an AI chatbot surface. Narrow (single plugin) but real for websites that deploy this AI support ticket system.
Time-based blind SQL injection via the unsanitized 'sort_by' parameter in list endpoints; an attacker can extract data from the WordPress database (users, hashes, tickets) through timing side channels.
SupportCandy AI Customer Support Ticket System & Live Chatbot Agent WordPress plugin <= 3.5.3
Update the SupportCandy plugin to a version newer than 3.5.3 once the vendor releases a fix. Reference: https://plugins.svn.wordpress.org/supportcandy/
NVD CVE-2026-94539Plugin source reference
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →