CVE-2026-73350

WordPress SupportCandy plugin <= 3.5.1 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in SupportCandy <= 3.5.1 versions.


We have discovered 1,912 live websites that are affected by CVE-2026-73350.

Run a Free Instant Scan




Affected Software

Product  Supportcandy
Category Wordpress Plugins
Vulnerable Domains1,912 live websites (100% of Supportcandy install base)
Vulnerable Versions
  • from 0 through 3.5.1
Vulnerable Versions Count53 versions ( 100% of all versions)


Common Weakness Enumeration

CWE-266 Incorrect Privilege Assignment



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • hackthesoul | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-73350
United States600 websites



Germany163 websites
Italy147 websites
GB106 websites
France86 websites
Brazil65 websites
Spain63 websites
Canada46 websites
Netherlands44 websites
India40 websites

Website Distribution by TLD

Number of websites using CVE-2026-73350
.com750 websites
.it124 websites
.org101 websites
.de78 websites
.net53 websites
.co.uk52 websites
.com.br50 websites
.nl34 websites
.ru30 websites
.es30 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73350

Top websites that are affected by CVE-2026-73350. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.app Bulgaria**,***
**********.com United States**,***
*********************.org United States**,***
****************.com GB**,***
********.pt United States**,***
***.ch Switzerland**,***
************.net United States**,***
***************.com United States**,***
**************.com United States**,***
*****.sv El Salvador***,***
See full domain list

FAQ

CVE-2026-73350 is Incorrect Privilege Assignment in Supportcandy
A total of 1,912 websites have been identified as vulnerable to CVE-2026-73350, based on global website indexing conducted by WebTechSurvey.
The Supportcandy is affected by the CVE-2026-73350 vulnerability.
Supportcandy versions up to and including 3.5.1 are vulnerable to CVE-2026-73350.