{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/customer-support-ticket-system--helpdesk-plugin-for-wordpress--6.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15011"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Customer Support Ticket System \u0026 Helpdesk plugin for WordPress \u003c= 6.0.5"],"_cs_severities":["critical"],"_cs_tags":["code-injection","wordpress","web-application","plugin-vulnerability","php"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eA critical code injection vulnerability, identified as CVE-2026-15011, has been discovered in the Customer Support Ticket System \u0026amp; Helpdesk plugin for WordPress, affecting all versions up to and including 6.0.5. This flaw stems from insufficient validation of the 'path' parameter, which is then used in dynamic function invocation. This allows unauthenticated attackers to remotely invoke arbitrary parameterless PHP functions. A key aspect of this vulnerability is that the required security nonce for exploitation is publicly emitted via \u003ccode\u003ewp_localize_script\u003c/code\u003e on any public-facing page that renders the plugin's \u003ccode\u003e[emd_form]\u003c/code\u003e shortcode. This makes the exploitation vector readily accessible to unauthenticated visitors without needing any prior authentication or special privileges. Successful exploitation can lead to significant disruption of website functionality or the exposure of sensitive data stored on the server.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e\u003cstrong\u003eInitial Discovery\u003c/strong\u003e: An attacker identifies a WordPress instance running the vulnerable Customer Support Ticket System \u0026amp; Helpdesk plugin, specifically version 6.0.5 or earlier.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNonce Acquisition\u003c/strong\u003e: The attacker accesses a public-facing page on the target WordPress site that renders the \u003ccode\u003e[emd_form]\u003c/code\u003e shortcode. From the \u003ccode\u003ewp_localize_script\u003c/code\u003e output on this page, the attacker extracts the necessary security nonce.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ePayload Crafting\u003c/strong\u003e: The attacker constructs a malicious HTTP GET or POST request targeting an endpoint handled by the vulnerable plugin. This request includes the 'path' parameter, whose value is crafted to be the name of an arbitrary parameterless PHP function (e.g., \u003ccode\u003ephpinfo\u003c/code\u003e, \u003ccode\u003eexit\u003c/code\u003e, \u003ccode\u003ereadfile\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExploitation Request\u003c/strong\u003e: The crafted HTTP request, incorporating the acquired nonce and the malicious 'path' parameter, is sent to the vulnerable WordPress website.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDynamic Function Invocation\u003c/strong\u003e: The vulnerable plugin's code receives the request. Due to the lack of proper input validation, the attacker-controlled value in the 'path' parameter is directly used in a dynamic function invocation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eImpact Execution\u003c/strong\u003e: The specified PHP function executes on the server. Depending on the invoked function, this can lead to immediate disruption of the website's operation (e.g., \u003ccode\u003edie()\u003c/code\u003e function) or the exposure of sensitive information (e.g., \u003ccode\u003ephpinfo()\u003c/code\u003e output, reading arbitrary files via \u003ccode\u003ereadfile()\u003c/code\u003e).\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15011 can lead to severe consequences for affected WordPress sites. Attackers can leverage the ability to invoke arbitrary parameterless PHP functions to disrupt the normal operation of the website, potentially rendering it inaccessible or non-functional. Furthermore, this vulnerability can be abused to expose sensitive information residing on the server, including configuration files, user data, or database credentials, which could lead to further compromise or data breaches. While specific victim counts are not available, all organizations utilizing the Customer Support Ticket System \u0026amp; Helpdesk plugin for WordPress in affected versions are at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Customer Support Ticket System \u0026amp; Helpdesk plugin for WordPress to a version patched against CVE-2026-15011.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for unusual HTTP requests targeting plugin-specific endpoints, especially those containing unexpected or suspicious values in query parameters that might indicate attempts to exploit CVE-2026-15011.\u003c/li\u003e\n\u003cli\u003eImplement web application firewall (WAF) rules to detect and block requests that attempt dynamic PHP function invocation via query parameters, particularly targeting the 'path' parameter mentioned in CVE-2026-15011.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T10:19:51Z","date_published":"2026-07-23T10:19:51Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-ticket-system-code-injection/","summary":"A critical code injection vulnerability, CVE-2026-15011, affects the Customer Support Ticket System \u0026 Helpdesk plugin for WordPress versions up to and including 6.0.5, allowing unauthenticated attackers to invoke arbitrary parameterless PHP functions via the 'path' parameter, potentially disrupting site functionality or exposing sensitive information without prior authentication.","title":"Critical Code Injection Vulnerability in WordPress Customer Support Ticket System \u0026 Helpdesk Plugin (CVE-2026-15011)","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-ticket-system-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Customer Support Ticket System \u0026 Helpdesk Plugin for WordPress \u003c= 6.0.5","version":"https://jsonfeed.org/version/1.1"}