VendorsWP Support Pluswp_support_plus_responsive_ticket_systemany version
Vulnerabilities

WP Support Plus Responsive Ticket System any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2014-10389
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
Published 2019-08-22 · Modified
9.8EPSS 0.022
CVE-2018-1000131
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.
Published 2018-03-14 · Modified
9.8EPSS 0.021
CVE-2016-10930
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
Published 2019-08-22 · Modified
9.8EPSS 0.020
CVE-2014-10387
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
Published 2019-08-22 · Modified
9.8EPSS 0.018
CVE-2014-10390
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
Published 2019-08-22 · Modified
9.1EPSS 0.025
CVE-2014-10391
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2019-15331
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
Published 2019-08-22 · Modified
6.1EPSS 0.009
CVE-2014-10388
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
Published 2019-08-22 · Modified
5.3EPSS 0.013