CVE-2026-81022: SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
SupportCandy WordPress plugin versions 3.3.6 through 3.5.2 are affected. The issue is fixed in version 3.5.3.
Does exploitation require an authenticated WordPress or SupportCandy account?
No. An unauthenticated user can exploit the issue to read support-ticket contents.
What does an attacker need to target a ticket?
The vulnerability involves submitting a per-ticket authorization code. The plugin fails to validate the submitted code before disclosing the real code to the requester.
How can I determine whether my site may be affected?
Check the installed SupportCandy plugin version. Versions before 3.5.3, including 3.3.6 through 3.5.2, may allow unauthenticated disclosure of ticket contents.