
CVE-2026-0683 The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field filter in all versions… https://www.cve.org/CVERecord?id=CVE-2026-0683
Post summary
The statement announces that the SupportCandy WordPress plugin is vulnerable to SQL injection through a custom field filter, but does not provide evidence of exploitation, PoC, or remediation.

