Junglewise Threat Intelligence

CVE-2025-69179: Theme passion Support Ticket Management System privilege escalation

CVE-2025-69179 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Executive brief

The Support Ticket Management System plugin for WordPress, which provides customer service and ticketing functionality, contains a critical security flaw. An unauthenticated attacker can exploit this vulnerability to gain administrative control over the website. This could lead to full site takeover, theft of customer data, and complete service disruption.

Technical details

The Support Ticket Management System plugin for WordPress (versions <= 1.9) suffers from an unauthenticated privilege escalation vulnerability due to incorrect privilege assignment (CWE-266). The flaw allows a remote, unauthenticated attacker to elevate their privileges, potentially gaining full administrative access to the WordPress site. The vulnerability is categorized under OWASP A7: Identification and Authentication Failures. As of the advisory date, no official patch has been released by the vendor, and users are advised to seek alternative mitigation strategies such as web application firewalls.

Affected products

  • Theme passion Support Ticket Management System <= 1.9

Timeline

  • 2025-11-11: other: Vulnerability reported by researcher Phat RiO
  • 2026-05-28: advisory: Patchstack published advisory details
  • 2026-06-17: disclosed: CVE published to NVD

References