CVE-2018-21002: CSRF
Published Aug 27, 2019
·Updated
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
Affected Software
1 affected component
joomsky Js Help Desk Wordpress<2.0.6
Event History
Aug 27, 2019
CVE Published
via MITRE·11:24 AM
Data Sourced
via MITRE·11:24 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21002?
The severity of CVE-2018-21002 is high.
2
What is the affected software for CVE-2018-21002?
The affected software for CVE-2018-21002 is the js-support-ticket plugin before version 2.0.6 for WordPress.
3
How does CVE-2018-21002 impact WordPress?
CVE-2018-21002 allows for cross-site request forgery (CSRF) attacks on WordPress sites using the js-support-ticket plugin before version 2.0.6.
4
How can I fix CVE-2018-21002?
To fix CVE-2018-21002, it is recommended to update the js-support-ticket plugin to version 2.0.6 or later.
5
Where can I find more information about CVE-2018-21002?
You can find more information about CVE-2018-21002 on the WordPress plugin page for js-support-ticket: https://wordpress.org/plugins/js-support-ticket/#developers