WpsupportplusCVEs & Vulnerabilities

9 CVEs affecting Wpsupportplus products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wp support plus responsive ticket system 9
CVE-2019-15331MEDIUM

The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

22 Aug 2019
6.1
CVSS
CVE-2016-10930CRITICAL

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

22 Aug 2019
9.8
CVSS
CVE-2014-10391MEDIUM

The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

22 Aug 2019
6.1
CVSS
CVE-2014-10390CRITICAL

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

22 Aug 2019
9.1
CVSS
CVE-2014-10389CRITICAL

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

22 Aug 2019
9.8
CVSS
CVE-2014-10388MEDIUM

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

22 Aug 2019
5.3
CVSS
CVE-2014-10387CRITICAL

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

22 Aug 2019
9.8
CVSS
CVE-2019-7299MEDIUM

A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.

21 Mar 2019
6.1
CVSS
CVE-2018-1000131CRITICAL

Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.

14 Mar 2018
9.8
CVSS
← PrevPage 1 / 1Next →
Wpsupportplus CVEs & Vulnerabilities — 9 Tracked