plugin

Wp Support Plus Responsive Ticket System Vulnerabilities

34 known security issues reported for the Wp Support Plus Responsive Ticket System WordPress plugin. Most recent disclosed Jun 18, 2026.

4 critical 6 high 4 medium

Running Wp Support Plus Responsive Ticket System on your site? Check whether your installed version is affected.

Scan your site free

Support Plus Responsive Ticket System <= 9.1.2 - Insecure Direct Object Reference to Unauthenticated Support Ticket Access

medium

The Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 9.1.2. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 9.1.2
Fix:
No patched version reported
Disclosed:
Jun 18, 2026

CVE-2026-11875 on NVD →

Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection

high

The Support Plus Responsive Ticket System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 9.1.2. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
7.5
Affected:
up to 9.1.2
Fix:
No patched version reported
Disclosed:
Jun 9, 2026

CVE-2026-11590 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 4.2 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Aug 22, 2019

CVE-2014-10390 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 4.1 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.

Affected:
up to 4.1
Fixed in:
4.1
Disclosed:
Aug 22, 2019

CVE-2014-10391 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 4.2 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Aug 22, 2019

CVE-2014-10388 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 4.2 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Aug 22, 2019

CVE-2014-10387 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 7.1.0 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Aug 22, 2019

CVE-2016-10930 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 4.2 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Aug 22, 2019

CVE-2014-10389 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 9.1.2 (closed)

unknown

[en] The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

Affected:
up to 9.1.2
Fixed in:
9.1.2
Disclosed:
Aug 22, 2019

CVE-2019-15331 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 9.1.2 (closed)

unknown

[en] A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includ...

Affected:
up to 9.1.2
Fixed in:
9.1.2
Disclosed:
Mar 18, 2019

CVE-2019-7299 on NVD →

WP Support Plus Responsive Ticket System <= 9.1.1 - Stored Cross-Site Scripting

high

The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.

CVSS:
7.2
Affected:
up to 9.1.2
Fixed in:
9.1.2
Disclosed:
Feb 4, 2019

CVE-2019-15331 on NVD →

WP Support Plus Responsive Ticket System <= 9.1.1 - Stored Cross-Site Scripting

medium

A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/aj...

CVSS:
6.1
Affected:
up to 9.1.2
Fixed in:
9.1.2
Disclosed:
Feb 4, 2019

CVE-2019-7299 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 9.0.3 (closed)

unknown

[en] Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This...

Affected:
up to 9.0.3
Fixed in:
9.0.3
Disclosed:
Mar 14, 2018

CVE-2018-1000131 on NVD →

WP Support Plus Responsive Ticket System <= 9.0.2 - SQL Injection

critical

Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appears to be exploitable via web site, without login. This vuln...

CVSS:
9.8
Affected:
up to 9.0.2
Fixed in:
9.0.3
Disclosed:
Feb 25, 2018

CVE-2018-1000131 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.8 (closed)

unknown

Remote Code Execution (RCE) vulnerability found in WordPress WP Support Plus Responsive Ticket System plugin (versions <=8.0.7).

Affected:
up to 8.0.8
Fixed in:
8.0.8
Disclosed:
Nov 20, 2017

WP Support Plus Responsive Ticket System <= 8.0.7 - Arbitrary File Upload

high

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including 8.0.7. This is due to insufficient file type validation on the wpsp_upload_attachment AJAX action which makes it possible for authenticated attackers to upload arbitrary files that...

CVSS:
8.8
Affected:
up to 8.0.8
Fixed in:
8.0.8
Disclosed:
Nov 11, 2017

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.8 (closed)

unknown

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including 8.0.7. This is due to insufficient file type validation on the wpsp_upload_attachment AJAX action which makes it possible for authenticated attackers to upload arbitrary files that...

Affected:
up to 8.0.8
Fixed in:
8.0.8
Disclosed:
Nov 11, 2017

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 7.1.5 (closed)

unknown

WordPress plugin WP Support Plus Responsive Ticket System 7.1.3 (earlier versions and 7.1.4) vulnerable to privilege escalation. It is possible to log in as any user without knowing password due to the incorrect usage of "wp_set_auth_cookie()". Update the plugin to the latest version (atleast 7.1.5).

Affected:
up to 7.1.5
Fixed in:
7.1.5
Disclosed:
Jan 10, 2017

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 7.1.4 (closed)

unknown

This plugin is prone to an SQL injection vulnerability. It allows an attacker to modify data, compromise the access and application or exploit hidden vulnerabilities in the underlying database. Update the plugin.

Affected:
up to 7.1.4
Fixed in:
7.1.4
Disclosed:
Dec 16, 2016

WP Support Plus Responsive Ticket System <= 7.1.4 - SQL Injection

high

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to generic SQL Injection via the "$_POST[‘cat_id’]" parameter in versions up to, and including, 7.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

CVSS:
8.8
Affected:
up to 7.1.4
Fixed in:
8.0.0
Disclosed:
Dec 12, 2016

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.0 (closed)

unknown

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to generic SQL Injection via the "$_POST[‘cat_id’]" parameter in versions up to, and including, 7.1.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it p...

Affected:
up to 8.0.0
Fixed in:
8.0.0
Disclosed:
Dec 12, 2016

Support Plus Responsive Ticket System < 7.1.0 - Insecure Direct Object Reference

high

The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.

CVSS:
7.5
Affected:
up to 7.1.0
Fixed in:
7.1.0
Disclosed:
Sep 20, 2016

CVE-2016-10930 on NVD →

WP Support Plus Responsive Ticket System <= 7.1.4 - Authentication Bypass

critical

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 7.1.4. This is due to the plugin only requiring a valid email for the loginGuestFacebook AJAX action which is passed to the wp_set_auth_cookie() function and will log the user in as...

CVSS:
9.8
Affected:
up to 8.0.0
Fixed in:
8.0.0
Disclosed:
Jun 12, 2016

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.0 (closed)

unknown

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 7.1.4. This is due to the plugin only requiring a valid email for the loginGuestFacebook AJAX action which is passed to the wp_set_auth_cookie() function and will log the user in as...

Affected:
up to 8.0.0
Fixed in:
8.0.0
Disclosed:
Jun 12, 2016

WP Support Plus Responsive Ticket System <= 4.1 - Improper Authentication

critical

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.

CVSS:
9.8
Affected:
up to 4.1
Fixed in:
4.2
Disclosed:
Nov 15, 2014

CVE-2014-10389 on NVD →

WP Support Plus Responsive Ticket System <= 4.1 - Directory Traversal

high

The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.

CVSS:
7.5
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Nov 15, 2014

CVE-2014-10390 on NVD →

WP Support Plus Responsive Ticket System <= 4.0 - JavaScript Injection

medium

The WP Support Plus Responsive Ticket System plugin for WordPress is vulnerable to JavaScript Injection in versions up to, and including, 4.0. This makes it possible for unauthenticated attackers to inject potentially malicious JavaScript code into the vulnerable service.

CVSS:
6.1
Affected:
up to 4.0
Fixed in:
4.1
Disclosed:
Nov 4, 2014

CVE-2014-10391 on NVD →

Support Plus Responsive Ticket System <= 4.1 - SQL Injection

critical

The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has SQL injection.

CVSS:
9.8
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Sep 9, 2014

CVE-2014-10387 on NVD →

Support Plus Responsive Ticket System <= 4.1 - Full Path Disclosure

medium

The Support Plus Responsive Ticket System plugin before 4.2 for WordPress has full path disclosure.

CVSS:
5.3
Affected:
up to 4.2
Fixed in:
4.2
Disclosed:
Sep 9, 2014

CVE-2014-10388 on NVD →

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 2.1 (closed)

unknown

There are 4 multiple vulnerabilities in this plugin. 1. SQL injection. 2. Full path disclosure. With this vulnerability full path to the file will be shown to the user after the file has been uploaded. 3. Directory traversal that allows download any file from the server. 4. Broken authentication. Update the plugi...

Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Sep 9, 2014

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.8 (closed)

unknown

WP Support Plus Responsive Ticket System &lt;= 8.0.7 allows anyone to upload PHP files with extensions like &quot;.phtml&quot;, &quot;.php4&quot;, &quot;.php5&quot;, and so on, all of which are run as if their extension was &quot;.php&quot; on most hosting platforms. This is because &quot;includes/admin/attachment/u...

Affected:
up to 8.0.8
Fixed in:
8.0.8

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.8 (closed)

unknown

WP Support Plus Responsive Ticket System &lt;= 8.0.7 allows anyone to upload PHP files with extensions like &quot;.phtml&quot;, &quot;.php4&quot;, &quot;.php5&quot;, and so on, all of which are run as if their extension was &quot;.php&quot; on most hosting platforms. This is because &quot;includes/admin/attachment/u...

Affected:
up to 8.0.8
Fixed in:
8.0.8

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.0 (closed)

unknown

You can login as anyone without knowing password because of incorrect usage of wp_set_auth_cookie().

Affected:
up to 8.0.0
Fixed in:
8.0.0

WP Support Plus Responsive Ticket System [wp-support-plus-responsive-ticket-system] < 8.0.0 (closed)

unknown

Type user access: any user. $_POST[&lsquo;cat_id&rsquo;] is not escaped. Is accessible for any user.

Affected:
up to 8.0.0
Fixed in:
8.0.0

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database