Junglewise Threat Intelligence

CVE-2026-15011: emarket-design Customer Support Ticket System code injection in path parameter

CVE-2026-15011 · Severity: critical · CVSS 9.8 · Published 2026-07-23

Executive brief

The Customer Support Ticket System & Helpdesk plugin for WordPress, which manages customer service requests, contains a critical security flaw. An unauthenticated attacker can remotely trigger internal functions on the website, potentially leading to the exposure of sensitive data or a complete disruption of the site's services. This is possible because the plugin fails to properly secure a specific communication shortcut (nonce) that is visible to any visitor on pages where a support form is displayed.

Technical details

The vulnerability is classified as Code Injection (CWE-94) resulting from improper validation of the 'path' parameter, which is used in a dynamic function invocation. An unauthenticated attacker can exploit this by supplying the name of a parameterless PHP function to be executed by the server. While such attacks typically require a security nonce, this plugin publicly leaks the required nonce via 'wp_localize_script' on any page where the '[emd_form]' shortcode is present. This allows for remote, unauthenticated exploitation. The impact includes potential information disclosure and denial of service. A patch was introduced in version 6.0.6 (referenced via changeset 3617122).

Affected products

  • emarket-design Customer Support Ticket System & Helpdesk up to, and including, 6.0.5

Timeline

  • 2026-07-23: advisory: NVD publication date
  • 2026-07-23: disclosed: Wordfence threat intelligence report published

References