WooCommerce Support Ticket System < 18.5 - Unauthenticated Arbitrary File Deletion
critical
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to 18.5 (exclusive). This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code executio...
- CVSS:
- 9.1
- Affected:
- up to 18.5
- Fixed in:
- 18.5
- Disclosed:
- Mar 20, 2026
CVE-2026-32522 on NVD →
WooCommerce Support Ticket System [woocommerce-support-ticket-system] < 17.9
unknown
[en] The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8. This makes it possible...
- Affected:
- up to 17.9
- Fixed in:
- 17.9
- Disclosed:
- Feb 1, 2025
CVE-2024-13775 on NVD →
WooCommerce Support Ticket System <= 17.8 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Deletion and Information Exposure
medium
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8. This makes it possible for a...
- CVSS:
- 5.4
- Affected:
- up to 17.8
- Fixed in:
- 17.9
- Disclosed:
- Jan 31, 2025
CVE-2024-13775 on NVD →
WooCommerce Support Ticket System [woocommerce-support-ticket-system] < 17.8
unknown
[en] The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the s...
- Affected:
- up to 17.8
- Fixed in:
- 17.8
- Disclosed:
- Nov 9, 2024
CVE-2024-10625 on NVD →
WooCommerce Support Ticket System [woocommerce-support-ticket-system] < 17.8
unknown
[en] The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the af...
- Affected:
- up to 17.8
- Fixed in:
- 17.8
- Disclosed:
- Nov 9, 2024
CVE-2024-10627 on NVD →
WooCommerce Support Ticket System [woocommerce-support-ticket-system] < 17.8
unknown
[en] The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level access and above,...
- Affected:
- up to 17.8
- Fixed in:
- 17.8
- Disclosed:
- Nov 9, 2024
CVE-2024-10626 on NVD →
WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload
critical
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary files on the affecte...
- CVSS:
- 9.8
- Affected:
- up to 17.7
- Fixed in:
- 17.8
- Disclosed:
- Nov 8, 2024
CVE-2024-10627 on NVD →
WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion
critical
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server...
- CVSS:
- 9.8
- Affected:
- up to 17.6
- Fixed in:
- 17.8
- Disclosed:
- Nov 8, 2024
CVE-2024-10625 on NVD →
WooCommerce Support Ticket System <= 17.7 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to d...
- CVSS:
- 8.8
- Affected:
- up to 17.7
- Fixed in:
- 17.8
- Disclosed:
- Nov 8, 2024
CVE-2024-10626 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database