CVE-2026-94539 | psmplugins SupportCandy Plugin up to 3.5.3 on WordPress sort_by sql injection (EUVD-2026-91879)
A vulnerability categorized as critical has been discovered in psmplugins SupportCandy Plugin up to 3.5.3 on WordPress. Affected by this issue is some unknown functionality. Executing a manipulation of the argument sort_by can lead to sql injection.
This vulnerability is registered as CVE-2026-94539. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More