WordPress security by component
SupportCandy – Helpdesk & Customer Support Ticket System
Plugin description
SupportCandy – Helpdesk & Customer Support Ticket System adds a WordPress helpdesk system for creating, assigning, organizing, and responding to customer support tickets.
SupportCandy – Helpdesk & Customer Support Ticket System (supportcandy) is a WordPress plugin with 21 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
supportcandyLatest vulnerability
CVE-2026-81022: SupportCandy discloses ticket access codes without validating the requester
SupportCandy versions 3.3.6 to before 3.5.3 disclose a ticket's real authorization code before validating the caller's submitted code. An unauthenticated attacker can obtain the secret and use it to read any support ticket's contents.
| Safe version |
|
||
|---|---|---|---|
| Sep 09, 2026 |
CVE-2026-81022
SupportCandy discloses ticket access codes without validating the requester
SupportCandy versions 3.3.6 to before 3.5.3 disclose a ticket's real authorization code before validating the caller's submitted code. An unauthenticated attacker can obtain the secret and use it to read any support ticket's contents.
|
3.5.3 |
CVE5.3
NVDPending
|
| Sep 09, 2026 |
CVE-2026-81021
SupportCandy permits unauthenticated downloads of protected attachments
SupportCandy versions 3.2.9 to before 3.5.3 omit authorization on a support-ticket attachment download path. An unauthenticated attacker can enumerate sequential attachment IDs and download protected customer files.
|
3.5.3 |
CVE5.3
NVDPending
|
| Aug 18, 2026 |
CVE-2026-73350
SupportCandy: Privilege escalation or authentication bypass
SupportCandy is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is n/a through 3.5.1.
|
3.5.2 |
CVE8.2
NVDPending
|
| Jul 13, 2026 |
CVE-2026-57711
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.4.8.
|
3.4.9 |
CVE6.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-54826
SupportCandy: Broken access control
SupportCandy is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 3.4.6.
|
3.4.7 |
CVE7.6
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25321
SupportCandy: A security weakness
SupportCandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 31, 2026 |
CVE-2026-1251
SupportCandy – Helpdesk & Customer Support Ticket System: Broken access control
SupportCandy – Helpdesk & Customer Support Ticket System is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 31, 2026 |
CVE-2026-0683
SupportCandy – Helpdesk & Customer Support Ticket System: SQL injection
SupportCandy – Helpdesk & Customer Support Ticket System is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67598
SupportCandy: Cross-site request forgery
SupportCandy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 20, 2025 |
CVE-2025-10658
SupportCandy – Helpdesk & Customer Support Ticket System: Privilege escalation or authentication bypass
SupportCandy – Helpdesk & Customer Support Ticket System is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 07, 2025 |
CVE-2024-13552
SupportCandy – Helpdesk & Customer Support Ticket System: Broken access control
SupportCandy – Helpdesk & Customer Support Ticket System is affected by broken access control. The vulnerable path is reachable without authentication. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 11, 2024 |
CVE-2024-27991
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 19, 2023 |
CVE-2023-2805
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVEPending
NVD7.2
|
| Jun 19, 2023 |
CVE-2023-2719
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 02, 2023 |
CVE-2023-1730
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 07, 2022 |
CVE-2021-24880
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD5.4
|
| Feb 07, 2022 |
CVE-2021-24879
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD8.8
|
| Feb 07, 2022 |
CVE-2021-24878
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVEPending
NVD6.1
|
| Feb 07, 2022 |
CVE-2021-24843
SupportCandy: A security weakness
SupportCandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD6.5
|
| Feb 07, 2022 |
CVE-2021-24839
SupportCandy: Cross-site request forgery
SupportCandy is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVEPending
NVD7.5
|
| Apr 18, 2019 |
CVE-2019-11223
Supportcandy: A security weakness
Supportcandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVEPending
NVD9.8
|