Impact
The vulnerability is caused by the plugin failing to validate a per-ticket authorization code before revealing the real code in the response. Because any user can request the code, unauthenticated visitors can access the full contents of any support ticket, compromising the confidentiality of user data and potentially exposing sensitive business information. The weakness is a direct form of information exposure, allowing attackers to read data they should not have access to.
Affected Systems
WordPress sites that use the SupportCandy plugin in any release before version 3.5.3, specifically the series 3.3.6 through 3.5.2.
Risk and Exploitability
The flaw is not mitigated by authentication controls and can be triggered by any external party that knows or guesses a ticket ID, making the attack surface wide. The CVSS score is 5.3, indicating a medium severity, but because the flaw provides unauthenticated access to potentially sensitive support content, the overall risk is considered high. The EPSS score is less than 1%, and the entry is not listed in CISA’s KEV catalog; still, the exploit is trivial to craft once the ticket request structure is understood.
OpenCVE Enrichment