SupportCandy
supportcandy · eklenti
SupportCandy için bilinen güvenlik açıkları. Sitenizde bu bileşenin hangi sürümünün çalıştığını WP Lens ile saniyede öğrenin.
11 bilinen açık
1 kritik · 2 kayıt için istismar kodu yayımlanmış · son kayıt 18 Ağu 2026
Güvenlik açıkları
- Kritik 9.8
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrar
- Yüksek 8.2
WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability
- Yüksek 7.6
WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnerability
- Orta 6.5
WordPress SupportCandy plugin <= 3.4.8 - Cross Site Scripting (XSS) vulnerability
- Orta 6.5
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) SQL Injection via Number Field Filter
- Orta 6.5
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover
- Orta 6.5
WordPress SupportCandy plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability
- Orta 5.4
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.4.4 - Authenticated (Subscriber+) Insecure Direct Object Reference
- Orta 5.3
WordPress SupportCandy plugin <= 3.4.4 - Broken Access Control vulnerability
- Orta 4.3
WordPress SupportCandy plugin <= 3.4.1 - Cross Site Request Forgery (CSRF) vulnerability
- Orta 4.3
SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.0 - Insecure Direct Object Reference