{"id":70578,"date":"2025-09-20T15:31:43","date_gmt":"2025-09-20T12:01:43","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-10658-supportcandy-wordpress-plugin-authentication-bypass-vulnerability\/"},"modified":"2025-09-20T15:31:43","modified_gmt":"2025-09-20T12:01:43","slug":"cve-2025-10658-supportcandy-wordpress-plugin-authentication-bypass-vulnerability","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-10658-supportcandy-wordpress-plugin-authentication-bypass-vulnerability\/","title":{"rendered":"CVE-2025-10658 &#8211; SupportCandy WordPress Plugin Authentication Bypass Vulnerability"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-10658<br \/>\n<br \/>\n<strong>Published : <\/strong> Sept. 20, 2025, 9:10 a.m. | 1\u00a0hour, 56\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>The SupportCandy \u2013 Helpdesk &amp; Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest login. This makes it possible for unauthenticated attackers to bypass authentication and gain unauthorized access to customer support tickets by brute forcing the 6-digit OTP code.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 6.5 | MEDIUM<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-10658 Published : Sept. 20, 2025, 9:10 a.m. | 1\u00a0hour, 56\u00a0minutes ago Description : The SupportCandy \u2013 Helpdesk &amp; Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.3.7. This is due to missing rate limiting on the OTP verification for guest &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-70578","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/70578","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=70578"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/70578\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=70578"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=70578"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=70578"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}