SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-11875

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-07-09 · Last synced 2026-08-08

CyberRota Analysis

AI-Generated

The WP Support Plus Responsive Ticket System plugin for WordPress versions up to 9.1.2 is vulnerable due to the lack of signing and verification for its guest-session cookie. This flaw allows unauthenticated attackers to forge cookies, enabling them to impersonate any ticket owner and gain unauthorized access to their support tickets, including reading, replying to, and closing them. WordPress site administrators using this plugin should prioritize patching or updating to mitigate the risk of unauthorized access to sensitive support information.

CVE
CVE-2026-11875
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticated attackers to forge it and impersonate any ticket owner (identified by email address) to read, reply to, and close that person's support tickets.