Supportcandy

WordPress plugin · supportcandy · WordPress.org ↗
0
Critical
0
High
2
Known total
0
Unfixed
Running Supportcandy on your site? WP Alerts checks your installed version against every entry below and emails you only when one affects you. Free, no tracking.
Scan a site Monitor my sites →
SeverityVulnerabilityAffectedFixed inCVEPublished
MEDIUM
CVSS 5.3
SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure
CVE.org
>=3.2.9, <3.5.3 v3.5.3 CVE-2026-81021 Sep 9, 2026
MEDIUM
CVSS 5.3
SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak
CVE.org
>=3.3.6, <3.5.3 v3.5.3 CVE-2026-81022 Sep 9, 2026

Data aggregated from WPVulnerability, NVD/NIST, ENISA EUVD, CVE.org and WordPress.org. Provided as-is; verify with the plugin author before acting. Disclaimer.