天下漏洞,尽知其名
MEDIUM

CVE-2026-94539 SupportCandy 插件 SQL 注入漏洞

影响认证攻击者可注入 SQL 查询,窃取数据库敏感信息

AI 研判

WordPress 插件 SupportCandy(AI 客服工单系统与实时聊天机器人)存在基于时间的 SQL 注入漏洞,影响 3.5.3 及之前所有版本。漏洞源于 sort_by 参数未充分转义且 SQL 查询未做预处理,攻击者可向既有查询追加恶意 SQL 语句。

影响范围

SupportCandy

SupportCandy 插件所有版本至 3.5.3(含 3.5.3)。

漏洞详情

漏洞类型为基于时间的 SQL 注入。由于 sort_by 参数缺乏转义、SQL 查询未使用预处理语句,攻击者可将额外 SQL 查询拼接到原有查询中,并通过时间延迟判断注入结果,从而逐位提取数据库中的敏感信息。

利用条件与风险

利用需攻击者同时具备 Subscriber 及以上 WordPress 角色,以及配置了 'Assign Agents' 权限的 SupportCandy Agent 账户,属于认证后利用,实战风险中等。

修复建议

官方修复方案暂无公开信息,建议升级至 3.5.3 之后版本(如有);临时缓解可限制 Agent 账户权限、对 sort_by 参数进行严格校验或部署 WAF 拦截 SQL 注入特征。

原始情报

The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to time-based SQL Injection via the ‘sort_by’ parameter in all versions up to, and including, 3.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with custom-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. Exploitation requires the authenticated attacker to hold both a Subscriber-level (or higher) WordPress role and a SupportCandy Agent account with the ‘Assign Agents’ permission configured.