CVE-2021-24839: SupportCandy < 2.2.5 - Unauthenticated Arbitrary Ticket Deletion
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsctickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the setdeletepermanentlybulkticket settingaction. Other actions may be affected as well.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24839?
CVE-2021-24839 is a vulnerability in the SupportCandy WordPress plugin before version 2.2.5.
What is the severity of CVE-2021-24839?
The severity of CVE-2021-24839 is high, with a CVSS score of 7.5.
How does CVE-2021-24839 impact the SupportCandy plugin?
CVE-2021-24839 allows unauthenticated users to delete arbitrary tickets in the SupportCandy plugin.
How can I fix CVE-2021-24839?
To fix CVE-2021-24839, update the SupportCandy plugin to version 2.2.5 or later.
Where can I find more information about CVE-2021-24839?
You can find more information about CVE-2021-24839 at this reference: [https://wpscan.com/vulnerability/5e6e63c2-2675-4b8d-9b94-c16c525a1a0e]