PT-2026-63591 · WordPress · Customer Support Ticket System & Helpdesk
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Customer Support Ticket System & Helpdesk plugin for WordPress versions prior to 6.0.6
Description
Code Injection is possible due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. Unauthenticated attackers can invoke arbitrary parameterless PHP functions, which may disrupt site functionality or expose sensitive information. This is achievable via the
path parameter. The required nonce is publicly emitted via wp localize script when the [emd form] shortcode is rendered on any public-facing page, allowing the endpoint to be reached without authentication or privileges.Recommendations
Update the Customer Support Ticket System & Helpdesk plugin for WordPress to version 6.0.6 or later.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Customer Support Ticket System & Helpdesk