CVE-2015-7670: Support Ticket System Project Support Ticket System

Critical severity, CVSS 9.8. EPSS: 3.1% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.

Affected products

Published 2017-09-26. Last modified 2026-06-17.