Description
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SupportCandy plugin for WordPress versions 3.5.1 and earlier suffers from an unauthenticated broken authentication flaw, identified as CWE-266. This defect allows an attacker to impersonate any user without prior login credentials, granting access to administrative functions within the WordPress site. The vulnerability does not directly lead to code execution but compromises the integrity and confidentiality of the site by enabling unauthorized changes, data exfiltration, or further lateral movement.

Affected Systems

WordPress sites that have installed the SupportCandy plugin version 3.5.1 or older. The affected product is the plugin released by PSM Plugins, commonly referred to as SupportCandy. No other WordPress core components are listed as impacted by this specific flaw.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity, and the exploitability is inferred to be remote, since the flaw is triggered via unauthenticated HTTP requests to the plugin’s endpoints. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Consequently, while the exact likelihood of exploitation is unclear, the high CVSS out of the box recommends urgent attention, especially for sites exposed to the internet.

Generated by OpenCVE AI on August 18, 2026 at 16:22 UTC.

Remediation

Vendor Solution

Update the WordPress SupportCandy Plugin to the latest available version (at least 3.5.2).


OpenCVE Recommended Actions

  • Upgrade the SupportCandy plugin to version 3.5.2 or later to eliminate the broken authentication flaw.
  • Review the plugin's configuration and reset any custom settings that may have been exploited before applying the upgrade.
  • If a critical update cannot be applied immediately, disable or remove the plugin from the WordPress installation and replace it with a vetted alternative.

Generated by OpenCVE AI on August 18, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Psm Plugins
Psm Plugins supportcandy
Wordpress
Wordpress wordpress
Vendors & Products Psm Plugins
Psm Plugins supportcandy
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Title WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Psm Plugins Supportcandy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T19:48:21.085Z

Reserved: 2026-08-12T10:51:20.619Z

Link: CVE-2026-73350

cve-icon Vulnrichment

Updated: 2026-08-18T19:39:35.453Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:03.377

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73350

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T16:30:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment