CVE-2026-94378 WordPress SupportCandy 插件存储型 XSS 漏洞
影响具有订阅者及以上权限的攻击者可注入恶意脚本,在用户访问页面时执行
SupportCandy 是 WordPress 的 AI 客服工单系统与实时聊天机器人插件。该插件在所有 3.5.3 及之前版本中,由于对 'name' 参数输入过滤和输出转义不足,存在存储型跨站脚本漏洞。攻击者可注入任意 Web 脚本,当其他用户访问被注入页面时脚本将被执行。
影响范围
SupportCandy 插件所有版本至 3.5.3(含 3.5.3)。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS),成因是插件对 'name' 参数未进行充分的输入清理和输出转义。攻击者需具备订阅者及以上权限,可将恶意脚本持久化存储于页面中。当其他用户访问该页面时,脚本会在其浏览器中执行。利用该漏洞需禁用 'Register user if not exists' 设置,而该设置为默认配置。
利用条件与风险
利用前提是攻击者拥有订阅者及以上权限,且目标站点保持 'Register user if not exists' 设置为禁用状态(默认)。实战中可导致会话劫持、页面篡改或钓鱼攻击,风险等级为中等。
修复建议
建议更新 SupportCandy 插件至 3.5.3 之后的修复版本;临时缓解措施包括启用 'Register user if not exists' 设置或限制低权限用户注册,具体修复方案请关注官方公告。
The SupportCandy – AI Customer Support Ticket System & Live Chatbot Agent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘name’ parameter in all versions up to, and including, 3.5.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This exploit chain requires the ‘Register user if not exists’ setting to be disabled, which is its default configuration.