İçeriğe atla
Noroxi

SupportCandy

supportcandy · eklenti

SupportCandy için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.

11 bilinen açık

1 kritik · 2 kayıt için istismar kodu yayımlanmış · son kayıt 18 Ağu 2026

Güvenlik açıkları

  • CVE-2019-11223

    An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrar

    Kritik 9.8
  • CVE-2026-73350

    WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability

    Yüksek 8.2
  • CVE-2026-54826

    WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnerability

    Yüksek 7.6
  • CVE-2026-57711

    WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2026-0683

    SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter

    Orta 6.5
  • CVE-2025-10658

    SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover

    Orta 6.5
  • CVE-2024-27991

    WordPress SupportCandy plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability

    Orta 6.5
  • CVE-2026-1251

    SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference

    Orta 5.4
  • CVE-2026-25321

    WordPress SupportCandy plugin <= 3.4.4 - Broken Access Control vulnerability

    Orta 5.3
  • CVE-2025-67598

    WordPress SupportCandy plugin <= 3.4.1 - Cross Site Request Forgery (CSRF) vulnerability

    Orta 4.3
  • CVE-2024-13552

    SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference

    Orta 4.3

← Dizine dön