WordPress WP Support Plus Responsive Ticket System是WordPress基金会的一款适用于 WordPress 的一体化前端文章提交、用户注册、个人资料构建器、会员和用户目录插件。 WordPress WP Support Plus Responsive Ticket System 9.1.2及之前版本存在授权问题漏洞,该漏洞源于未对访客会话cookie进行签名或验证,导致未经身份验证的攻击者可以伪造cookie并冒充任意票据所有者读取、回复和关闭支持票据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Support Plus Responsive Ticket System | ≤ 9.1.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Support Plus Responsive Ticket System | 0 ~ 9.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12516 | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy | |
| CVE-2026-12517 | Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint | |
| CVE-2026-12270 | Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endp | |
| CVE-2026-11571 | Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Ar | |
| CVE-2026-11869 | WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subj |
No comments yet