CVE-2026-57711: WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability
Published Jul 13, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PSM Plugins SupportCandy supportcandy allows Stored XSS.This issue affects SupportCandy: from n/a through <= 3.4.8.
Affected Software
1 affected component
SupportCandy<=3.4.8
Event History
Jul 13, 2026
CVE Published
via MITRE·08:41 AM
Data Sourced
via MITRE·08:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges and network access. Exploitation also requires user interaction.
2
What is the expected impact if exploitation succeeds?
The CVSS vector rates confidentiality, integrity, and availability impact as low. It also indicates scope change, meaning the impact may extend beyond the initially affected security authority.