WordPress security by component
SupportCandy
Plugin description
SupportCandy is a WordPress component with 18 published CVE records in this archive. The latest tracked vulnerability was published Jul 13, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
supportcandyLatest vulnerability
CVE-2026-57711: SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.4.8.
| Safe version |
|
||
|---|---|---|---|
| Jul 13, 2026 |
CVE-2026-57711
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 3.4.8.
|
3.4.9 |
CVE6.5
NVDPending
|
| Jun 26, 2026 |
CVE-2026-54826
SupportCandy: A security weakness
SupportCandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.4.6.
|
3.4.7 |
CVE7.6
NVDPending
|
| Feb 19, 2026 |
CVE-2026-25321
SupportCandy: A security weakness
SupportCandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Jan 31, 2026 |
CVE-2026-1251
SupportCandy – Helpdesk & Customer Support Ticket System: A security weakness
SupportCandy – Helpdesk & Customer Support Ticket System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jan 31, 2026 |
CVE-2026-0683
SupportCandy – Helpdesk & Customer Support Ticket System: SQL injection
SupportCandy – Helpdesk & Customer Support Ticket System is affected by SQL injection. Exploitation requires at least subscriber-level access. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Dec 09, 2025 |
CVE-2025-67598
SupportCandy: Cross-site request forgery
SupportCandy is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Sep 20, 2025 |
CVE-2025-10658
SupportCandy – Helpdesk & Customer Support Ticket System: Privilege escalation or authentication bypass
SupportCandy – Helpdesk & Customer Support Ticket System is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Mar 07, 2025 |
CVE-2024-13552
SupportCandy – Helpdesk & Customer Support Ticket System: A security weakness
SupportCandy – Helpdesk & Customer Support Ticket System is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE4.3
NVDPending
|
| Apr 11, 2024 |
CVE-2024-27991
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jun 19, 2023 |
CVE-2023-2805
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Jun 19, 2023 |
CVE-2023-2719
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| May 02, 2023 |
CVE-2023-1730
SupportCandy: SQL injection
SupportCandy is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 07, 2022 |
CVE-2021-24880
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVD5.4
|
| Feb 07, 2022 |
CVE-2021-24879
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Feb 07, 2022 |
CVE-2021-24878
SupportCandy: Cross-site scripting
SupportCandy is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Feb 07, 2022 |
CVE-2021-24843
SupportCandy: A security weakness
SupportCandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVD6.5
|
| Feb 07, 2022 |
CVE-2021-24839
SupportCandy: Cross-site request forgery
SupportCandy is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE7.5
NVD7.5
|
| Apr 18, 2019 |
CVE-2019-11223
Supportcandy: A security weakness
Supportcandy is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE9.8
NVD9.8
|