Junglewise Threat Intelligence

CVE-2026-11589: WP Support Plus Responsive Ticket System unauthenticated stored XSS via file upload

CVE-2026-11589 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: WP Support Plus Responsive Ticket System. Vendors: WP Support Plus, Unknown.

Executive brief

The WP Support Plus Responsive Ticket System plugin for WordPress, which provides customer support ticketing functionality, contains a security flaw in its file upload system. This vulnerability allows anyone on the internet to upload malicious files to the website without needing to log in. If a site visitor or administrator views these files, an attacker could steal login sessions, redirect users to malicious websites, or perform actions on behalf of the administrator.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the WP Support Plus Responsive Ticket System plugin through version 9.1.2 due to insufficient validation of uploaded files. Unauthenticated attackers can upload files containing malicious JavaScript, such as HTML or SVG files, to a publicly accessible directory on the server. When these files are accessed by other users or administrators, the embedded script executes in the context of their browser session. This can lead to session hijacking, unauthorized administrative actions, or site defacement. As of the advisory date, no known fix is available.

Affected products

  • Unknown WP Support Plus Responsive Ticket System <= 9.1.2

Timeline

  • 2026-06-09: disclosed: Publicly published via WPScan
  • 2026-06-30: advisory: CVE published in NVD dataset

References

Related threats