
1万サイト以上が使用するWordPressのSupportCandyプラグインに、チケット添付ファイルへの安全でない直接オブジェクト参照(IDOR)の脆弱性。他人がアップロードしたファイルのIDを指定して投稿するとファイルにアクセスできる。CVE-2026-1251が採番。CVSSスコアは5.4。 https://securityboulevard.com/2026/02/disclosure-supportcandy-ticket-attachment-idor-cve-2026-1251/
Post summary
The post announces an IDOR vulnerability (CVE‑2026‑1251) in the SupportCandy WordPress plugin, detailing its type and severity, but provides no PoC, exploit, or patch information.
