CVE-2018-1000131
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injected that can result in filter the parameter. This attack appear to be exploitable via web site, without login. This vulnerability appears to have been fixed in 9.0.3 and later.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-89
- Affected
- wpsupportplus/wp support plus responsive ticket system
- Source
- cve@mitre.org
References
- https://github.com/00theway/exp/blob/master/wordpress/wpsupportplus.mdExploit, Third Party Advisory
- https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developersRelease Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9041Third Party Advisory
- https://github.com/00theway/exp/blob/master/wordpress/wpsupportplus.mdExploit, Third Party Advisory
- https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developersRelease Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9041Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.