PT-2026-56700 · WordPress · Wp-Support-Plus-Responsive-Ticket-System

·

CVE-2026-11875

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Support Plus Responsive Ticket System versions prior to 9.1.3
Description The plugin fails to sign or verify its guest-session cookie. This allows unauthenticated attackers to forge the cookie and impersonate any ticket owner by using their email address. Consequently, an attacker can read, reply to, and close support tickets belonging to other users.
Recommendations Update the plugin to version 9.1.3 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-11875

Affected Products

Wp-Support-Plus-Responsive-Ticket-System