CVE-2026-94539

CVE-2026-94539 published: The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the 'sort_by' parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplie...

View full NVD advisory → ← Back to CVE watch