WORDPRESS · JULY 2026 · EARLY WARNING

Customer Support Ticket System & Helpdesk Plugin for WordPress Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-15011Severity: CRITICAL

The Customer Support Ticket System & Helpdesk plugin for WordPress is reportedly vulnerable to code injection in versions up to 6.0.5, potentially allowing unauthenticated attackers to execute arbitrary PHP functions.

What happened

An early warning has been issued regarding a critical vulnerability in the Customer Support Ticket System & Helpdesk plugin for WordPress. The vulnerability, tracked as CVE-2026-15011, reportedly allows code injection via the 'path' parameter due to insufficient validation. This could enable unauthenticated attackers to invoke arbitrary PHP functions, potentially disrupting site functionality or exposing sensitive information.

The vulnerability affects all versions of the plugin up to and including 6.0.5. The required nonce is publicly emitted via wp_localize_script whenever the plugin's [emd_form] shortcode is rendered on any public-facing page, making the endpoint reachable by unauthenticated visitors.

As a precautionary measure, it is recommended to upgrade the Customer Support Ticket System & Helpdesk plugin to version 6.0.6 or later. For more detailed information, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If customer support ticket system & helpdesk plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats