Insecure Direct Object References in SupportCandy by WordPress
CVE-2026-54826
7.6HIGH
What is CVE-2026-54826?
The SupportCandy plugin versions up to 3.4.6 are susceptible to Insecure Direct Object References (IDOR), which could allow unauthorized users to access sensitive information by manipulating URL parameters. This vulnerability poses a serious risk to user privacy and data integrity, emphasizing the need for timely updates and security measures to mitigate potential exploits.
Affected Version(s)
SupportCandy <= 3.4.6