CVE-2026-81022
The SupportCandy WordPress plugin before 3.5.3 does not validate a submitted per-ticket authorization code before disclosing the real code to the requester, allowing unauthenticated users to read the contents of any support ticket.
- Published Sep 9, 2026
- CVSS 5.3 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available