CVE-2026-0683

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to SQL Injection via the Number-type custom field filter in all versions up to, and including, 3.4.4. This is due to insufficient escaping on the user-supplied operand value when using the equals operator and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with Subscriber-level access and above (customers), to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.


We have discovered 2,034 live websites that are affected by CVE-2026-0683.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains2,034 live websites (100% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.4.4
Vulnerable Versions Count53 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Jan 31, 2026
  • Updated - Feb 2, 2026

Credits

  • Supakiad S. (finder)

Website Distribution by Country

Number of websites using CVE-2026-0683
United States634 websites



Germany177 websites
Italy156 websites
GB118 websites
France92 websites
Iran72 websites
Brazil66 websites
Spain56 websites
India51 websites
Canada50 websites

Website Distribution by TLD

Number of websites using CVE-2026-0683
.com812 websites
.it128 websites
.org98 websites
.de81 websites
.net65 websites
.co.uk59 websites
.com.br51 websites
.fr35 websites
.es32 websites
.nl29 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-0683

Top websites that are affected by CVE-2026-0683. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
**********.com United States**,***
*********************.org United States**,***
****************.com GB**,***
********.pt United States**,***
***.ch Switzerland**,***
************.net United States**,***
***************.com United States**,***
*****.sv El Salvador***,***
*************.com United States***,***
See full domain list

FAQ

CVE-2026-0683 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Supportcandy
A total of 2,034 websites have been identified as vulnerable to CVE-2026-0683, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2026-0683 vulnerability.
Supportcandy versions up to and including 3.4.4 are vulnerable to CVE-2026-0683.