Impact
The SupportCandy plugin for WordPress versions 3.5.1 and earlier suffers from an unauthenticated broken authentication flaw, identified as CWE-266. This defect allows an attacker to impersonate any user without prior login credentials, granting access to administrative functions within the WordPress site. The vulnerability does not directly lead to code execution but compromises the integrity and confidentiality of the site by enabling unauthorized changes, data exfiltration, or further lateral movement.
Affected Systems
WordPress sites that have installed the SupportCandy plugin version 3.5.1 or older. The affected product is the plugin released by PSM Plugins, commonly referred to as SupportCandy. No other WordPress core components are listed as impacted by this specific flaw.
Risk and Exploitability
The CVSS score of 8.2 indicates a high severity, and the exploitability is inferred to be remote, since the flaw is triggered via unauthenticated HTTP requests to the plugin’s endpoints. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. Consequently, while the exact likelihood of exploitation is unclear, the high CVSS out of the box recommends urgent attention, especially for sites exposed to the internet.
OpenCVE Enrichment