The SupportCandy plugin for WordPress has a time-based SQL injection vulnerability in versions up to 3.5.3. Authenticated attackers with custom-level access and above can exploit this vulnerability to extract sensitive information from the database. This vulnerability requires attention from security teams, WordPress administrators, and developers who use the SupportCandy plugin. The vulnerability is caus [truncated]
The SupportCandy plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'name' parameter in versions up to 3.5.3. Authenticated attackers with subscriber-level access can inject web scripts, requiring the 'Register user if not exists' setting to be disabled. This vulnerability allows for potential user session hijacking and unauthorized actions via injected scripts. Defenders should [truncated]