WP Support Plus Responsive Ticket System

WP Support Plus Responsive Ticket System has 14 disclosed vulnerabilities in the WordSec catalog, reported between 2014 and 2026; 12 are fixed and 2 remain unpatched as of September 2026. Their average CVSS score is 7.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 4 critical and 6 high. 2014 was the busiest year with 5 disclosures.

The most common weakness is SQL Injection, behind 4 of the records (29%). Other recurring categories include Authorization Bypass Through User-Controlled Key, Cross-Site Scripting.

12 of the records (86%) have a vendor fix, while 2 remain unpatched. The oldest unresolved one dates back to 2026.

7 independent researchers contributed these findings, most of them (4) reported by Fikri Fadzil.

01234567891009.09.2014Today09.09.20149.8Support Plus Responsive Ticket System <= 4.1 - SQL Injection CVSS 9.8 · 09.09.20145.3Support Plus Responsive Ticket System <= 4.1 - Full Path Disclosure CVSS 5.3 · 09.09.201404.11.20146.1WP Support Plus Responsive Ticket System <= 4.0 - JavaScript Injection CVSS 6.1 · 04.11.201415.11.20149.8WP Support Plus Responsive Ticket System <= 4.1 - Improper Authentication CVSS 9.8 · 15.11.20147.5WP Support Plus Responsive Ticket System <= 4.1 - Directory Traversal CVSS 7.5 · 15.11.201412.06.20169.8WP Support Plus Responsive Ticket System <= 7.1.4 - Authentication Bypass CVSS 9.8 · 12.06.201620.09.20167.5Support Plus Responsive Ticket System < 7.1.0 - Insecure Direct Object Reference CVSS 7.5 · 20.09.201612.12.20168.8WP Support Plus Responsive Ticket System <= 7.1.4 - SQL Injection CVSS 8.8 · 12.12.201611.11.20178.8WP Support Plus Responsive Ticket System <= 8.0.7 - Arbitrary File Upload CVSS 8.8 · 11.11.201725.02.20189.8WP Support Plus Responsive Ticket System <= 9.0.2 - SQL Injection CVSS 9.8 · 25.02.201804.02.20196.1WP Support Plus Responsive Ticket System <= 9.1.1 - Stored Cross-Site Scripting CVSS 6.1 · 04.02.20197.2WP Support Plus Responsive Ticket System <= 9.1.1 - Stored Cross-Site Scripting CVSS 7.2 · 04.02.201909.06.20267.5Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection CVSS 7.5 · 09.06.202618.06.20265.3Support Plus Responsive Ticket System <= 9.1.2 - Insecure Direct Object Reference to Unauthenticated Support Ticket Access CVSS 5.3 · 18.06.2026

Strategic Overview

Avg CVSSHigh
7.8/ 10
Patch Coverage86%
Open

2

Fixed

12

Get automatic notifications for all WP Support Plus Responsive Ticket System vulnerabilities before they are exploited.

Most severe open issueCVSS 7.5CVE-2026-11590

Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection

Read the full analysis

Vulnerability Records

14 records
2026-06-18 00:00CVE-2026-11875
5.3
Medium
Kartik sharmaNo
2026-06-09 00:00CVE-2026-11590
7.5
High
Ayush SrivastavaNo
2019-02-04 00:00CVE-2019-7299
6.1
Medium
Christian AngelYes
2019-02-04 00:00CVE-2019-15331
7.2
High
Christian AngelYes
2018-02-25 00:00CVE-2018-1000131
9.8
Critical
00thewayYes
2017-11-11 00:00N/A
8.8
High
AnonymousYes
2016-12-12 00:00N/A
8.8
High
Lenon LeiteYes
2016-09-20 00:00CVE-2016-10930
7.5
High
AnonymousYes
2016-06-12 00:00N/A
9.8
Critical
Kacper SzurekYes
2014-11-15 00:00CVE-2014-10389
9.8
Critical
Fikri FadzilYes
Showing 1–10 of 14 reports

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C