CVE-2026-11590
WP Support Plus Responsive Ticket System
The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL statement, allowing unauthenticated users to perform SQL injection attacks.
- CVSS
- 8.6
- EPSS
- 0.26% 18.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.30