Wpsupportplus develops a responsive ticketing system for WordPress that serves as a support-management plugin with web-facing request and authentication surfaces. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across input-handling and access-control weakness classes including cross-site scripting, SQL injection, improper authentication, and insufficient input validation, typical of server-side plugin code that processes untrusted user submissions. Defenders running this plugin should prioritize security updates and restrict administrative access; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wpsupportplus over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-10389CRITICAL The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication. | Aug 22, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-10387CRITICAL The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection. | Aug 22, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-1000131CRITICAL Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email | Mar 14, 2018 | 9.8 | 28 | NO | NO |
CVE-2016-10930CRITICAL The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number. | Aug 22, 2019 | 9.8 | 24 | NO | NO |
CVE-2014-10390CRITICAL The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal. | Aug 22, 2019 | 9.1 | 23 | NO | NO |
CVE-2019-15331MEDIUM The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection. | Aug 22, 2019 | 6.1 | 21 | NO | NO |
CVE-2014-10391MEDIUM The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection. | Aug 22, 2019 | 6.1 | 17 | NO | NO |
CVE-2019-7299MEDIUM A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers | Mar 21, 2019 | 6.1 | 17 | NO | NO |
CVE-2014-10388MEDIUM The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure. | Aug 22, 2019 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wpsupportplus.
Media articles that mention a CVE ID that affects a product developed by Wpsupportplus — matched by CVE ID, not by vendor name.