Executive brief
The WP Support Plus Responsive Ticket System plugin for WordPress, which provides customer support ticketing functionality, contains a security flaw that allows unauthorized individuals to access or modify the website's database. By sending a specially crafted request, an attacker could steal sensitive customer information, administrative credentials, or disrupt the site's operations. This vulnerability is particularly serious because it can be exploited by anyone on the internet without needing a login account.
Technical details
The WP Support Plus Responsive Ticket System plugin (up to version 9.1.2) is vulnerable to an unauthenticated SQL injection. The root cause is the failure to sanitize or validate user-supplied array keys within the 'filter[elements]' parameter before incorporating them into a SQL query. An attacker can exploit this by sending a crafted network request to the affected WordPress site, allowing for the execution of arbitrary SQL commands. This can lead to full database compromise, including the extraction of sensitive data or modification of records. As of the advisory date, there is no known fix or patch available for this issue.
Affected products
- Unknown WP Support Plus Responsive Ticket System <= 9.1.2
Timeline
- 2026-06-09: disclosed: Vulnerability publicly published by WPScan.
- 2026-06-30: advisory: CVE-2026-11590 published in the NVD.