Vulnerabilities
Vulnerable Software
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 7.1.0 for WordPress has insecure direct object reference via a ticket number.
CVSS Score
9.8
EPSS Score
0.008
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has SQL injection.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVSS Score
5.3
EPSS Score
0.002
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has incorrect authentication.
CVSS Score
9.8
EPSS Score
0.008
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has directory traversal.
CVSS Score
9.1
EPSS Score
0.005
Published
2019-08-22
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-22
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.
CVSS Score
9.8
EPSS Score
0.008
Published
2018-03-14


Contact Us

Shodan ® - All rights reserved