Executive brief
The Customer Support Ticket System & Helpdesk plugin for WordPress, which manages customer service requests, contains a critical security flaw. An unauthenticated attacker can remotely trigger internal functions on the website, potentially leading to the exposure of sensitive data or a complete disruption of the site's services. This is possible because the plugin fails to properly secure a specific communication shortcut (nonce) that is visible to any visitor on pages where a support form is displayed.
Technical details
The vulnerability is classified as Code Injection (CWE-94) resulting from improper validation of the 'path' parameter, which is used in a dynamic function invocation. An unauthenticated attacker can exploit this by supplying the name of a parameterless PHP function to be executed by the server. While such attacks typically require a security nonce, this plugin publicly leaks the required nonce via 'wp_localize_script' on any page where the '[emd_form]' shortcode is present. This allows for remote, unauthenticated exploitation. The impact includes potential information disclosure and denial of service. A patch was introduced in version 6.0.6 (referenced via changeset 3617122).
Affected products
- emarket-design Customer Support Ticket System & Helpdesk up to, and including, 6.0.5
Timeline
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: disclosed: Wordfence threat intelligence report published
References
- https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/class-install-deactivate.php
- https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/common-functions.php
- https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/common-functions.php
- https://plugins.trac.wordpress.org/browser/wp-ticket/tags/6.0.5/includes/emd-form-builder-lite/emd-form-frontend.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3617122%40wp-ticket&new=3617122%40wp-ticket
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f9e2ad4b-716a-4a2d-87c0-2f351bd13884?source=cve