Medium severity5.3NVD Advisory· Published Jul 9, 2026· Updated Jul 9, 2026
CVE-2026-11875
CVE-2026-11875
Description
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.
Affected products
1- Range: <=9.1.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.