CVE 6.5 MEDIUM

SupportCandy – Helpdesk & Customer Support Ticket System <= 3.3.7 - Authentication Bypass to Support Session Takeover_CVE-2025-10658

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Description

The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass authentication and gain unauthorized access to customer support tickets by brute forcing the 6-digit OTP code.

Basic Information

ID CVE-2025-10658
Source Wordfence
Published Sep 20, 2025 at 06:43

Affected Product

Vendor psmplugins
Product SupportCandy – Helpdesk & Customer Support Ticket System
Version *
Affected Versions psmplugins SupportCandy – Helpdesk & Customer Support Ticket System *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.