Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-1251 — AI Deep Analysis Summary

CVSS 5.4 · Medium

Q1What is this vulnerability? (Essence + Consequences)

🚨 **IDOR Vulnerability**: The SupportCandy plugin does not validate the user-controlled `description_attachments` parameter in the `add_reply` function.…

Q2Root Cause? (CWE/Flaw)

🛠️ **Root Cause**: CWE-284 (Insecure Direct Object References). ❌ Lack of permission checks on user-supplied attachment IDs allows arbitrary file association.

Q3Who is affected? (Versions/Components)

⚠️ **Scope**: All versions (including 3.4.4 and earlier). 💻 Component: WordPress Plugin SupportCandy – Helpdesk & Customer Support Ticket System.

Q4What can hackers do? (Privileges/Data)

🔓 **What Hackers Can Do**: Requires only subscriber-level or higher privileges. 📎 Steal attachments uploaded by others, bind them to their own tickets, enabling data theft and privilege escalation.

Q5Is exploitation threshold high? (Auth/Config)

🔐 **Low Exploitation Barrier**: Only authenticated users (subscriber level or above) are needed. 🌐 No special configuration required; attackers can directly submit malicious parameters via the API.

Q6Is there a public Exp? (PoC/Wild Exploitation)

🔍 **No Public PoC**: Official data does not provide a PoC. ⚠️ No known in-the-wild exploitation reports, but risk is high; immediate remediation is recommended.

Q7How to self-check? (Features/Scanning)

🔎 **Self-Check Method**: Inspect the `class-wpsc-individual-ticket.php` file and locate the `add_reply` function. 🔍 Check whether the `description_attachments` parameter validates user permissions.

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Officially Fixed**: Refer to Trac changeset #3448376. 🛡️ Patch has been released; upgrade to the latest version.

Q9What if no patch? (Workaround)

🛡️ **Temporary Mitigation**: Disable attachment upload functionality or restrict ticket operation permissions.…

Q10Is it urgent? (Priority Suggestion)

🔥 **High Priority!** CVSS 3.1 (C:L/I:L/A:N), high risk of data leakage. ⚠️ Immediate upgrade or temporary hardening recommended to prevent exploitation.