Impact
The SupportCandy WordPress plugin, in versions prior to 3.5.3, fails to perform an authorization check on the ticket attachment download path. An unauthenticated attacker can enumerate sequential attachment identifiers and download customer‑uploaded files, exposing sensitive data that was intended to be protected. This flaw directly compromises the confidentiality of support‑ticket attachments and can lead to a broader compromise of customer information.
Affected Systems
WordPress sites that use the SupportCandy plugin from version 3.2.9 through 3.5.2 are affected. Any instance of the plugin deployed on a public WordPress installation meets the vulnerability criteria.
Risk and Exploitability
The CVSS score is 5.3, and the EPSS score is < 1%, while the issue is not in the CISA KEV catalog. The vulnerability can be leveraged over the web by unauthenticated users who can guess valid attachment identifiers, so the attack vector is web-based and does not require privileged access. Given the potential for significant customer data exposure, the risk level should be considered high, particularly for installations that expose support‑ticket functionality to untrusted users.
OpenCVE Enrichment