Security Advisory

CVE-2021-24839

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-07 15:47:09
Last updated 2024-08-03 19:42:17
Assigner WPScan
State PUBLISHED

Description

The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CSRF checks in its wpsc_tickets AJAX action, which could allow unauthenticated users to call it and delete arbitrary tickets via the set_delete_permanently_bulk_ticket setting_action. Other actions may be affected as well.