CVE-2026-73350: WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.
Affected Software
1 affected component
wordpress/supportcandy<=3.5.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SupportCandy pluginto a version that resolves this vulnerability.Fixed in 3.5.2
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any site running SupportCandy version 3.5.1 or earlier is identified as affected. The vulnerability is remotely reachable and requires no authentication or user interaction.
2
What can be done if patching is not immediately possible?
The provided information does not state whether a default SupportCandy configuration is affected, nor does it provide mitigations or detection guidance. Until an update or vendor guidance is available, treat exposed installations of version 3.5.1 or earlier as requiring review.