CVE-2021-24843

MEDIUM

SupportCandy WordPress <2.2.7 - CSRF

Title source: llm

Description

The SupportCandy WordPress plugin before 2.2.7 does not have CRSF check in its wpsc_tickets AJAX action, which could allow attackers to make a logged in admin call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action.

Exploits (1)

github NO CODE 2 stars
by tomorroisnew · poc
https://github.com/tomorroisnew/CVE/tree/main/CVE-2021-24843

Scores

CVSS v3 6.5
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Details

CWE
CWE-352
Status published
Products (1)
supportcandy/supportcandy < 2.2.7
Published Feb 07, 2022
Tracked Since Feb 18, 2026