CVE-2019-7299
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in…
Does this matter?
Lower severity and a low EPSS score (1.66%). Track it; it rarely justifies an emergency change on its own.
Description
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in wp-content/plugins/wp-support-plus-responsive-ticket-system/includes/ajax/submit_ticket.php.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.66% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- wpsupportplus/wp support plus responsive ticket system
- Source
- cve@mitre.org
References
- https://cert.kalasag.com.ph/news/research/cve-2019-7299-stored-xss-in-wp-support-plus-responsive-ticket-system/Exploit, Third Party Advisory
- https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developersRelease Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9235Third Party Advisory
- https://cert.kalasag.com.ph/news/research/cve-2019-7299-stored-xss-in-wp-support-plus-responsive-ticket-system/Exploit, Third Party Advisory
- https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/#developersRelease Notes, Third Party Advisory
- https://wpvulndb.com/vulnerabilities/9235Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.