logo

WordPress Helpdesk Plugin Unauthenticated Code Injection — CVE-2026-15011

ID: 458402ba-45b2-5926-b8a5-66d397b32e67

STIX ID: report--458402ba-45b2-5926-b8a5-66d397b32e67

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-26

...
...

**CVE-2026-15011 — critical unauthenticated PHP code injection in the Customer Support Ticket System & Helpdesk WordPress plugin (<= 6.0.5).** The plugin improperly passes a user-controlled `path` parameter into dynamic PHP function invocation while exposing a validation nonce, allowing remote unauthenticated attackers to execute arbitrary PHP functions (e.g., system(), file_put_contents(), eval()), achieve remote code execution, write webshells, and exfiltrate data; the issue is fixed in version 6.0.6 and immediate updates and mitigation steps (logs audit, webshell scanning, WAF rules) are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.