Junglewise Threat Intelligence

CVE-2026-57711: PSM Plugins SupportCandy Stored XSS

CVE-2026-57711 · Severity: medium · CVSS 6.5 · Published 2026-07-13

Technologies: PSM Plugins SupportCandy. Vendors: PSM Plugins.

Executive brief

SupportCandy is a popular WordPress plugin used to manage customer support tickets and helpdesk operations. A security vulnerability in versions up to 3.4.8 allows an attacker with basic user permissions to inject malicious scripts into the website. This could lead to unauthorized actions being performed on behalf of other users, including administrators, potentially compromising user data or site control.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the PSM Plugins SupportCandy plugin for WordPress due to improper neutralization of input during web page generation. The flaw allows an authenticated attacker with low-level privileges to inject malicious scripts into certain fields that are later rendered for other users. Because the vulnerability is 'stored,' the payload remains on the server and executes in the context of any user (including administrators) who views the affected page. This can lead to session hijacking, unauthorized configuration changes, or further privilege escalation. The issue is addressed in version 3.4.9.

Affected products

  • PSM Plugins SupportCandy <= 3.4.8

Timeline

  • 2026-07-13: disclosed
  • 2026-07-13: advisory
  • 3.4.9: patched: Fixed in version 3.4.9

References