CVE-2026-11590: Unknown Wp Support Plus Responsive Ticket System
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
Affected products
- Unknown Wp Support Plus Responsive Ticket System: up to and including 9.1.2
Published 2026-06-30. Last modified 2026-06-30.