Description
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
Published: 2026-09-09
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patching
AI Analysis

Impact

The vulnerability is caused by the plugin failing to validate a per-ticket authorization code before revealing the real code in the response. Because any user can request the code, unauthenticated visitors can access the full contents of any support ticket, compromising the confidentiality of user data and potentially exposing sensitive business information. The weakness is a direct form of information exposure, allowing attackers to read data they should not have access to.

Affected Systems

WordPress sites that use the SupportCandy plugin in any release before version 3.5.3, specifically the series 3.3.6 through 3.5.2.

Risk and Exploitability

The flaw is not mitigated by authentication controls and can be triggered by any external party that knows or guesses a ticket ID, making the attack surface wide. The CVSS score is 5.3, indicating a medium severity, but because the flaw provides unauthenticated access to potentially sensitive support content, the overall risk is considered high. The EPSS score is less than 1%, and the entry is not listed in CISA’s KEV catalog; still, the exploit is trivial to craft once the ticket request structure is understood.

Generated by OpenCVE AI on September 9, 2026 at 20:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SupportCandy plugin to version 3.5.3 or later, which validates authorization codes before disclosure.
  • If an upgrade is not immediately possible, remove or disable the SupportCandy plugin entirely until a patch is applied.
  • Restrict the plugin’s support ticket endpoints to authenticated administrators using site-level access controls or additional WordPress security plugins.
  • Review support ticket logs for any unauthorized access and audit the plugin configuration to ensure no other exposed APIs remain.

Generated by OpenCVE AI on September 9, 2026 at 20:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Supportcandy
Supportcandy supportcandy
Wordpress
Wordpress wordpress
Vendors & Products Supportcandy
Supportcandy supportcandy
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
Title SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak
References

Subscriptions

Supportcandy Supportcandy
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-15T06:24:49.346Z

Reserved: 2026-08-26T14:41:02.758Z

Link: CVE-2026-81022

cve-icon Vulnrichment

Updated: 2026-09-09T15:33:15.765Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:17.060

Modified: 2026-09-09T16:17:10.087

Link: CVE-2026-81022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor