logo

Disclosure: SupportCandy Ticket Attachment IDOR (CVE-2026-1251)

ID: edaa80b3-3b00-54d0-b581-e6e6cce90066

STIX ID: report--edaa80b3-3b00-54d0-b581-e6e6cce90066

Feed Name: Security Boulevard

Threat Score
45/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

Author: Theklis Stefani

...
...

This report details CVE-2026-1251: an IDOR vulnerability in the SupportCandy WordPress helpdesk plugin (≤3.4.4) that permits authenticated, low-privileged users to supply arbitrary attachment IDs and thereby access or reassign files uploaded by other users. The vulnerability was responsibly disclosed to Wordfence, assigned CVE-2026-1251, and patched in SupportCandy 3.4.5; Wordfence rated it CVSS 5.4 (Medium).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.