PatchSiren

psmplugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM psmplugins CVE published 2026-10-03

CVE-2026-94539

The SupportCandy plugin for WordPress has a time-based SQL injection vulnerability in versions up to 3.5.3. Authenticated attackers with custom-level access and above can exploit this vulnerability to extract sensitive information from the database. This vulnerability requires attention from security teams, WordPress administrators, and developers who use the SupportCandy plugin. The vulnerability is caus [truncated]

MEDIUM psmplugins CVE published 2026-10-03

CVE-2026-94378

The SupportCandy plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'name' parameter in versions up to 3.5.3. Authenticated attackers with subscriber-level access can inject web scripts, requiring the 'Register user if not exists' setting to be disabled. This vulnerability allows for potential user session hijacking and unauthorized actions via injected scripts. Defenders should [truncated]