WordPress Helpdesk Plugin Unauthenticated Code Injection — CVE-2026-15011
ID: 458402ba-45b2-5926-b8a5-66d397b32e67
STIX ID: report--458402ba-45b2-5926-b8a5-66d397b32e67
Feed Name: CosmicBytez Labs
**CVE-2026-15011 — critical unauthenticated PHP code injection in the Customer Support Ticket System & Helpdesk WordPress plugin (<= 6.0.5).** The plugin improperly passes a user-controlled `path` parameter into dynamic PHP function invocation while exposing a validation nonce, allowing remote unauthenticated attackers to execute arbitrary PHP functions (e.g., system(), file_put_contents(), eval()), achieve remote code execution, write webshells, and exfiltrate data; the issue is fixed in version 6.0.6 and immediate updates and mitigation steps (logs audit, webshell scanning, WAF rules) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
