Zendesk Support for WordPress by Zendesk <= 1.8.4 - Convert comment to a ticket via CSRF
LANACOMMONVDB ID: c9669288-4365-413c-be0d-b403ffcf16be
The plugin does not have Cross-Site Request Forgery (CSRF) check when convert comment to a Zendesk ticket, which could allow attackers to make logged in admins create a Zendesk ticket from an arbitrary comment given they know the comment id.