WP Support Plus Responsive Ticket System Unauthenticated Session Cookie Forgery Vulnerability

Vulnerability

A vulnerability exists in the WP Support Plus Responsive Ticket System WordPress plugin, affecting versions through 9.1.2. The issue arises because the plugin does not sign or verify its guest-session cookie. This flaw allows unauthenticated attackers to forge the cookie and impersonate any ticket owner, identified by email address. Attackers can then read, reply to, and close the victim's support tickets.

Impact

Exploitation of this vulnerability allows for unauthorized access to support tickets, including the ability to read private ticket content, reply to tickets, and close tickets on behalf of the ticket owner.

Reproduction

To reproduce this vulnerability, the WP Support Plus Responsive Ticket System plugin version 9.1.2 must be active and configured to allow guest tickets. Once at least one ticket exists for a victim's email, an attacker can forge the guest-session cookie for that email. After crafting the cookie, the attacker can use it to access the victim's tickets through the WordPress AJAX endpoint, read private ticket threads, and inject replies using a nonce obtained from the ticket thread.

Added: Jul 9, 2026, 7:29 AM
Updated: Jul 9, 2026, 7:29 AM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
0.6
exploitability
9.3
remediation
0.0
relevance
9.2
threat
6.4
urgency
2.9
incentive
8.3

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.