Wpsupportplus
Wpsupportplus WP Support Plus Responsive Ticket System: vulnerabilidades y CVE
Wpsupportplus WP Support Plus Responsive Ticket System tiene 11 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses2
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-11875 | Media (5.3) | 0.32% | — | 9 jul 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified… |
| CVE-2026-11590 | Alta (8.6) | 0.45% | — | 30 jun 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection… |
| CVE-2019-15331 | Media (6.1) | 0.91% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. |
| CVE-2016-10930 | Crítica (9.8) | 2.0% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. |
| CVE-2014-10391 | Media (6.1) | 0.91% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. |
| CVE-2014-10390 | Crítica (9.1) | 2.5% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. |
| CVE-2014-10389 | Crítica (9.8) | 2.2% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. |
| CVE-2014-10388 | Media (5.3) | 1.3% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. |
| CVE-2014-10387 | Crítica (9.8) | 1.8% | — | 22 ago 2019 | The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. |
| CVE-2019-7299 | Media (6.1) | 1.7% | — | 21 mar 2019 | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML… |
| CVE-2018-1000131 | Crítica (9.8) | 2.1% | — | 14 mar 2018 | Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.