CVE-2025-10658: SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover
The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass authentication and gain unauthorized access to customer support tickets by brute forcing the 6-digit OTP code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10658?
CVE-2025-10658 is classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-10658?
To fix CVE-2025-10658, update the SupportCandy – Helpdesk & Customer Support Ticket System plugin to version 3.3.8 or later.
Who is affected by CVE-2025-10658?
All users of the SupportCandy – Helpdesk & Customer Support Ticket System plugin on WordPress versions up to and including 3.3.7 are affected by CVE-2025-10658.
What type of vulnerability is CVE-2025-10658?
CVE-2025-10658 is an authentication bypass vulnerability that allows unauthorized access through OTP verification flaws.
Can CVE-2025-10658 be exploited remotely?
Yes, CVE-2025-10658 can be exploited remotely by an unauthenticated attacker through the guest login feature.