SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-81021

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The SupportCandy WordPress plugin prior to version 3.5.3 is vulnerable due to a lack of authorization checks on support-ticket attachment download paths, enabling unauthenticated attackers to access and read protected customer-uploaded attachments by exploiting sequential attachment identifiers. This vulnerability poses a significant risk to user privacy and data security, making it critical for WordPress site administrators using this plugin to prioritize updating to the latest version.

CVE
CVE-2026-81021
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The SupportCandy WordPress plugin before 3.5.3 does not perform an authorization check on one of its support-ticket attachment download paths, allowing unauthenticated attackers to read protected customer-uploaded attachments by enumerating sequential attachment identifiers.