PT-2026-63591 · WordPress · Customer Support Ticket System & Helpdesk

·

CVE-2026-15011

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Customer Support Ticket System & Helpdesk plugin for WordPress versions prior to 6.0.6
Description Code Injection is possible due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. Unauthenticated attackers can invoke arbitrary parameterless PHP functions, which may disrupt site functionality or expose sensitive information. This is achievable via the path parameter. The required nonce is publicly emitted via wp localize script when the [emd form] shortcode is rendered on any public-facing page, allowing the endpoint to be reached without authentication or privileges.
Recommendations Update the Customer Support Ticket System & Helpdesk plugin for WordPress to version 6.0.6 or later.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15011

Affected Products

Customer Support Ticket System & Helpdesk