CyberRota Analysis
AI-GeneratedThe WP Support Plus Responsive Ticket System plugin for WordPress versions up to 9.1.2 is vulnerable due to the lack of signing and verification for its guest-session cookie. This flaw allows unauthenticated attackers to forge cookies, enabling them to impersonate any ticket owner and gain unauthorized access to their support tickets, including reading, replying to, and closing them. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk of unauthorized access to sensitive support information.
Original NVD Description
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.