Wordpress WP Support Plus Responsive Ticket System Multiple Vulnerabilities
Release date:
Updated on:
Affected Systems:
WordPress WP Support Plus Responsive Ticket System 2.0
Description:
Bugtraq id: 69736
CVE (CAN) ID: CVE-2014-3620
WP Support Plus Responsive Ticket System is a user Ticket System used on the WordPress website.
WP Support Plus Responsive Ticket System 2.0 and other versions have SQL injection, information leakage, directory traversal, and identity verification bypass vulnerabilities, successful exploitation of these vulnerabilities allows attackers to manipulate the SQL query logic to perform unoperated operations in the underlying database, read arbitrary files with constructed requests, and bypass authentication.
<* Source: Fikri Fadzil
*>
Suggestion:
Vendor patch:
WordPress
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wordpress.org/plugins/wp-support-plus-responsive-ticket-system/
This article permanently updates the link address: