Unrated severityNVD Advisory· Published Jul 9, 2026· Updated Jul 9, 2026
WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery
CVE-2026-11875
Description
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.
Affected products
1- Range: <=9.1.2
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/1c69692e-5d0c-42cf-9b3d-b722f2ba4231/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.