CVE-2025-67598

WordPress SupportCandy plugin <= 3.4.1 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forgery.This issue affects SupportCandy: from n/a through <= 3.4.1.


We have discovered 1,152 live websites that are affected by CVE-2025-67598.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains1,152 live websites (57% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.4.1
Vulnerable Versions Count48 versions ( 92% of all versions)



Details

  • Published - Dec 9, 2025
  • Updated - Jan 20, 2026

Credits

  • daroo | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-67598
United States309 websites



Germany88 websites
Italy87 websites
Iran62 websites
GB61 websites
France57 websites
Brazil43 websites
India32 websites
Spain31 websites
Russia25 websites

Website Distribution by TLD

Number of websites using CVE-2025-67598
.com445 websites
.it70 websites
.com.br37 websites
.org36 websites
.de32 websites
.net29 websites
.co.uk26 websites
.ru22 websites
.fr21 websites
.pl20 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67598

Top websites that are affected by CVE-2025-67598. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
****************.com GB**,***
********.pt United States**,***
***************.com United States**,***
*****.sv El Salvador***,***
*************.com United States***,***
***********.com United States***,***
*****************.com United States***,***
***********.com United States***,***
*************.com GB***,***
See full domain list

FAQ

A total of 1,152 websites have been identified as vulnerable to CVE-2025-67598, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2025-67598 vulnerability.
Supportcandy versions up to and including 3.4.1 are vulnerable to CVE-2025-67598.