CVE-2021-24843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
07/02/2022
Last modified:
10/02/2022

Description

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:supportcandy:supportcandy:*:*:*:*:*:wordpress:*:* 2.2.7 (excluding)