CVE-2019-11223: Supportcandy
Critical severity, CVSS 9.8. EPSS: 8.8% chance of exploitation in the next 30 days.
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
Affected products
- Supportcandy Supportcandy: up to and including 2.0.0
Published 2019-04-18. Last modified 2026-06-17.