Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter
critical
The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation. This makes it possible for unauthenticated a...
- CVSS:
- 9.8
- Affected:
- up to 6.0.5
- Fixed in:
- 6.0.6
- Disclosed:
- Jul 22, 2026
CVE-2026-15011 on NVD →
WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter
high
The WP Ticket plugin for WordPress is vulnerable to SQL Injection via the WordPress search query parameter (`s`) in versions up to, and including, 6.0.4 The plugin hooks WordPress's `posts_request` filter with `wp_ticket_com_posts_request()`, which calls `emd_author_search_results()` when the current request is an unau...
- CVSS:
- 7.5
- Affected:
- up to 6.0.4
- Fixed in:
- 6.0.5
- Disclosed:
- Jun 12, 2026
CVE-2026-9848 on NVD →
WP Ticket Customer Service Software & Support Ticket System <= 6.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and abov...
- CVSS:
- 6.4
- Affected:
- up to 6.0.2
- Fixed in:
- 6.0.3
- Disclosed:
- Sep 26, 2025
CVE-2025-60157 on NVD →
Multiple Plugins by eMarket Design <= Various Versions - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
Multiple plugins for WordPress by by eMarket Design are vulnerable to Stored Cross-Site Scripting in various versions due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 6.0.0
- Fixed in:
- 6.0.1
- Disclosed:
- Sep 23, 2025
CVE-2025-58915 on NVD →
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 6.0.3
unknown
[en] Deserialization of Untrusted Data vulnerability in emarket-design WP Ticket Customer Service Software & Support Ticket System allows Object Injection. This issue affects WP Ticket Customer Service Software & Support Ticket System: from n/a through 6.0.2.
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
- Disclosed:
- Aug 28, 2025
CVE-2025-53584 on NVD →
WP Ticket Customer Service Software & Support Ticket System <= 6.0.2 - Unauthenticated PHP Object Injection
high
The WP Ticket Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 6.0.2 via deserialization of untrusted input This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vuln...
- CVSS:
- 8.1
- Affected:
- up to 6.0.2
- Fixed in:
- 6.0.3
- Disclosed:
- Aug 25, 2025
CVE-2025-53584 on NVD →
Multiple Plugins by emarket-design <= Multiple Versions - Unauthenticated Limited Remote Code Execution
high
Multiple plugins for WordPress by emarket-design with the 'emd-form-builder-lite' package are vulnerable to Remote Code Execution in various versions via the emd_form_builder_lite_pagenum function. This is due to the plugin not properly validating user input before using it as a function name. This makes it possible fo...
- CVSS:
- 8.1
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.3
- Disclosed:
- Aug 5, 2025
CVE-2025-8420 on NVD →
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.13
unknown
Update the WordPress WP Ticket Customer Service Software & Support Ticket System plugin to the latest available version (at least 5.13).
Unknown discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress WP Ticket Customer Service Software & Support Ticket System Plugin. This could allow a malic...
- Affected:
- up to 5.13
- Fixed in:
- 5.13
- Disclosed:
- Jun 23, 2023
Customer Service Software & Support Ticket System <= 5.12.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- CVSS:
- 4.4
- Affected:
- up to 5.13
- Fixed in:
- 5.13
- Disclosed:
- Jun 22, 2023
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.13
unknown
The Customer Service Software & Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.12.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level pe...
- Affected:
- up to 5.13
- Fixed in:
- 5.13
- Disclosed:
- Jun 22, 2023
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.10.4
unknown
[en] The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 5.10.4
- Fixed in:
- 5.10.4
- Disclosed:
- Oct 18, 2021
CVE-2021-24622 on NVD →
Customer Service Software & Support Ticket System < 5.10.4 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Customer Service Software & Support Ticket System WordPress plugin before 5.10.4 does not sanitize or escape form fields before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 5.10.4
- Fixed in:
- 5.10.4
- Disclosed:
- Sep 20, 2021
CVE-2021-24622 on NVD →
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.6.0
unknown
Cross-Site Scripting (XSS) vulnerability found by WPScan security research team in WordPress WP Ticket Customer Service Software & Support Ticket System plugin (versions <= 5.5.1).
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.0
- Disclosed:
- Feb 15, 2021
Zebra_Form PHP library <= 2.9.8 - Reflected Cross-Site Scripting
medium
The Zebra_Form library present in the WP Inimat, Ad Swapper, Drug Search, Teaser Maker, and Customer Service Software & Support Ticket System Plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form' and 'control' parameters in versions up to, and including, 2.9.8 due to insufficient input sa...
- CVSS:
- 6.1
- Affected:
- up to 5.5.1
- Fixed in:
- 5.6.0
- Disclosed:
- Feb 14, 2021
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.6.0
unknown
The Zebra_Form library present in the WP Inimat, Ad Swapper, Drug Search, Teaser Maker, and Customer Service Software & Support Ticket System Plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'form' and 'control' parameters in versions up to, and including, 2.9.8 due to insufficient input sa...
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.0
- Disclosed:
- Feb 14, 2021
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 5.6.0
unknown
The Zebra_Form PHP library v2.9.8 (latest) and below, used by some WordPress plugins, is affected by reflected Cross-Site Scripting issues in its process.php file.
There is currently no patch available and the removal of this library is recommended.
- Affected:
- up to 5.6.0
- Fixed in:
- 5.6.0
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 6.0.3
unknown
- Affected:
- up to 6.0.3
- Fixed in:
- 6.0.3
CVE-2025-60157 on NVD →
Customer Support Ticket System & Helpdesk Plugin for WordPress [wp-ticket] < 6.0.1
unknown
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
CVE-2025-58915 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database