CVE-2015-7670

critical
Published 2017-09-26 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://wordpress.org/plugins/simple-support-ticket-system/#developers

Application impact

VendorProductVersionsFixed
support_ticket_system_projectsupport_ticket_system{"endIncluding":"1.2"}

References

CWEs

CWE-89

Verify integrity in audit chain (admin only). AS-IS.