CVE-2023-2719: Supportcandy

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

Affected products

Published 2023-06-19. Last modified 2026-06-17.