CVE-2025-9882: osTicket WP Bridge <= 1.9.2 - Cross-Site Request Forgery to Stored Cross-Site Scripting
The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9882?
CVE-2025-9882 has a moderate severity level due to its potential for Cross-Site Request Forgery.
How do I fix CVE-2025-9882?
To fix CVE-2025-9882, update the osTicket WP Bridge plugin to the latest version beyond 1.9.2.
Who is affected by CVE-2025-9882?
Any user operating the osTicket WP Bridge plugin version 1.9.2 or earlier is affected by CVE-2025-9882.
What type of vulnerability is CVE-2025-9882?
CVE-2025-9882 is classified as a Cross-Site Request Forgery vulnerability.
Can CVE-2025-9882 be exploited by unauthenticated attackers?
Yes, CVE-2025-9882 can be exploited by unauthenticated attackers due to missing nonce validation.