Executive brief
The Support Ticket Management System plugin for WordPress, which provides customer service and ticketing functionality, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to gain administrative control over the website. This could lead to full site takeover, theft of customer data, and complete service disruption.
Technical details
The Support Ticket Management System plugin for WordPress (versions <= 1.9) suffers from an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment (CWE-266). The flaw allows a remote, unauthenticated attacker to elevate their privileges, potentially gaining full administrative access to the WordPress site. The vulnerability is categorized under OWASP A7: Identification and Authentication Failures. As of the advisory date, no official patch has been released by the vendor, and users are advised to seek alternative mitigation strategies such as web application firewalls.
Affected products
- Theme passion Support Ticket Management System <= 1.9
Timeline
- 2025-11-11: other: Vulnerability reported by researcher Phat RiO
- 2026-05-28: advisory: Patchstack published advisory details
- 2026-06-17: disclosed: CVE published to NVD