CVE-2026-81022

The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 06:17

Updated : 2026-09-09 16:17


NVD link : CVE-2026-81022

Mitre link : CVE-2026-81022

CVE.ORG link : CVE-2026-81022


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor