CVE-2019-11223: Supportcandy

Critical severity, CVSS 9.8. EPSS: 8.8% chance of exploitation in the next 30 days.

An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.

Affected products

Published 2019-04-18. Last modified 2026-06-17.