CVE-2026-11590: Unknown Wp Support Plus Responsive Ticket System

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.

Affected products

  • Unknown Wp Support Plus Responsive Ticket System: up to and including 9.1.2

Published 2026-06-30. Last modified 2026-06-30.