CyberRota Analysis
AI-GeneratedThe SupportCandy WordPress plugin prior to version 3.5.3 is vulnerable due to inadequate validation of per-ticket authorization codes, which allows unauthenticated users to access and read the contents of any support ticket. This exposure could lead to unauthorized disclosure of sensitive information, impacting the confidentiality of user support interactions. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.