WordPress · Wp-Support-Plus-Responsive-Ticket-System · CVE-2026-11589
**Name of the Vulnerable Software and Affected Versions**
WP Support Plus Responsive Ticket System WordPress plugin versions prior to 9.1.3
**Description**
Insufficient validation of uploaded files allows unauthenticated users to upload files containing malicious JavaScript, such as HTML or SVG, to a publicly accessible location. This leads to Stored Cross-Site Scripting (XSS), a condition where malicious scripts are permanently stored on the target server and executed in the browser of site users and administrators.
**Recommendations**
Update the plugin to version 9.1.3 or later.