CVE-2021-24843: SupportCandy < 2.2.7 - Arbitrary Ticket Deletion via CSRF
The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsctickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the setdeletepermanentlybulkticket settingaction.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-24843?
CVE-2021-24843 is a vulnerability in the SupportCandy WordPress plugin before version 2.2.7 that allows attackers to delete arbitrary tickets.
What is the severity of CVE-2021-24843?
CVE-2021-24843 has a severity score of 6.5, which is classified as medium.
How does CVE-2021-24843 affect SupportCandy?
CVE-2021-24843 affects SupportCandy version up to and excluding 2.2.7.
How can an attacker exploit CVE-2021-24843?
An attacker can exploit CVE-2021-24843 by making a logged-in admin call the wpsc_tickets AJAX action and delete arbitrary tickets.
Is there a fix for CVE-2021-24843?
Yes, the fix for CVE-2021-24843 is to update the SupportCandy plugin to version 2.2.7 or later.