SupportCandy – Helpdesk & Customer Support Ticket System

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Authentication vulnerability in SupportCandy – Helpdesk & Customer Support Ticket System 3.3.7

    Fixed

    A popular plugin called SupportCandy, used for customer support tickets on WordPress websites, has a security flaw. This flaw allows hackers to bypass the authentication process and access customer s...

    Read More
  • Access violation vulnerability in SupportCandy – Helpdesk & Customer Support Ticket System 3.3.0

    Fixed

    The SupportCandy plugin for WordPress, which helps with customer support tickets, has a security vulnerability that allows unauthorized access to attachments. This means that someone who is not suppo...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Customer Support Ticket System 3.2.3

    Fixed

    The SupportCandy plugin for WordPress has a security issue that allows hackers to inject harmful code onto web pages. This can only be done by someone who has access to the website and has at least s...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 3.1.6

    Fixed

    The SupportCandy plugin for WordPress is not secure in versions up to, and including, 3.1.6. An attacker can use the 'id' parameter in the /wp-json/supportcandy/v2/agents/ REST route to send addition...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 3.1.6

    Fixed

    The SupportCandy plugin for WordPress is vulnerable to security risks in versions up to 3.1.6. Unauthenticated attackers can use a parameter called 'agents[]' to add extra commands to existing SQL qu...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.2.7

    Fixed

    The SupportCandy plugin for WordPress had a security issue before version 2.2.7. People with a low level of access such as Contributor could use it to perform an attack called Cross-Site Scripting. Th...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.0.1

    Fixed

    A security issue has been discovered in the SupportCandy plugin

    Read More
  • Access violation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.2.4

    Fixed

    The SupportCandy WordPress plugin had a security flaw before version 2.2.5. This flaw meant that unauthorized people could use a setting called “set_delete_permanently_bulk_ticket” to delete ticke...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.2.7

    Fixed

    The SupportCandy WordPress plugin before version 2.2.7 was vulnerable to attack. If an attacker was logged in as an administrator

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.2.6

    Fixed

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 3.1.4

    Fixed

    The SupportCandy plugin for WordPress has a security flaw that could let unauthenticated attackers access sensitive information from the database. This is because the 'parse_user_filters' function in ...

    Read More
  • Access violation vulnerability in SupportCandy – Helpdesk & Support Ticket System 3.1.3

    Fixed

    The SupportCandy plugin for WordPress can be a security risk in certain versions. When users of the plugin need help, they can upload documents to the plugin. This puts the documents in a specific fo...

    Read More
  • Input validation vulnerability in SupportCandy – Helpdesk & Support Ticket System 2.2.7

    Fixed

    The SupportCandy plugin for WordPress websites had a security issue in versions before 2.2.7. This could allow someone to access the ticket lists dashboard and set up a filter with malicious code. Thi...

    Read More