SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81022

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The SupportCandy WordPress plugin prior to version 3.5.3 is vulnerable due to inadequate validation of per-ticket authorization codes, which allows unauthenticated users to access and read the contents of any support ticket. This exposure could lead to unauthorized disclosure of sensitive information, impacting the confidentiality of user support interactions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-81022
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.