Vulnerabilities (CVE)

Filtered by vendor Wpsupportplus Subscribe
Filtered by product Wp Support Plus Responsive Ticket System
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-15331 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2020-08-24 4.3 MEDIUM 6.1 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 9.1.2 for WordPress has HTML injection.
CVE-2014-10391 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 4.3 MEDIUM 6.1 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 4.1 for WordPress has JavaScript injection.
CVE-2014-10388 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-08-29 5.0 MEDIUM 5.3 MEDIUM
The wp-support-plus-responsive-ticket-system plugin before 4.2 for WordPress has full path disclosure.
CVE-2019-7299 1 Wpsupportplus 1 Wp Support Plus Responsive Ticket System 2019-03-26 4.3 MEDIUM 6.1 MEDIUM
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.