← Back

Wpsupportplus

wpsupportplus

9 CVEs • 1 product

Products (1)

Click to collapse
Toggle

CVEs (9)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Jun 17, 2026
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML...Show more
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.Show less
1Wpsupportplus
1Wp Support Plus Responsive Ticket System
Nov 21, 2024
Mar 14, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result i...Show more
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.Show less