Customer Support Ticket System & Helpdesk Plugin for WordPress Under Investigation
The Customer Support Ticket System & Helpdesk plugin for WordPress is reportedly vulnerable to code injection in versions up to 6.0.5, potentially allowing unauthenticated attackers to execute arbitrary PHP functions.
What happened
An early warning has been issued regarding a critical vulnerability in the Customer Support Ticket System & Helpdesk plugin for WordPress. The vulnerability, tracked as CVE-2026-15011, reportedly allows code injection via the 'path' parameter due to insufficient validation. This could enable unauthenticated attackers to invoke arbitrary PHP functions, potentially disrupting site functionality or exposing sensitive information.
The vulnerability affects all versions of the plugin up to and including 6.0.5. The required nonce is publicly emitted via wp_localize_script whenever the plugin's [emd_form] shortcode is rendered on any public-facing page, making the endpoint reachable by unauthenticated visitors.
As a precautionary measure, it is recommended to upgrade the Customer Support Ticket System & Helpdesk plugin to version 6.0.6 or later. For more detailed information, consult the primary sources linked in the threat data.
How 0Day mitigates this
customer support ticket system & helpdesk plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.