WordPress · Supportcandy · CVE-2026-54826
**Name of the Vulnerable Software and Affected Versions**
SupportCandy versions prior to 3.4.7
**Description**
An Insecure Direct Object Reference (IDOR) exists, which occurs when an application provides direct access to objects based on user-supplied input, potentially allowing unauthorized access to data.
**Recommendations**
Update to a version newer than 3.4.6.