Impact
The vulnerability is an Incorrect Privilege Assignment flaw that allows an attacker who can exploit the Support Ticket plugin to elevate privileges. The flaw permits a user with insufficient credentials to assume the role of a higher‑privileged user, culminating in a full administrator account. The impact is the loss of confidentiality, integrity, and availability for the WordPress site, as an attacker can modify site settings, add or delete content, and access sensitive data.
Affected Systems
The affected system is the WordPress Support Ticket plugin from ThemePasion, versions from the earliest available build up through 1.9 inclusive. The plugin is installed as a standard WordPress plugin and does not require any special configuration settings to be vulnerable.
Risk and Exploitability
The CVSS score of 9.8 signifies critical severity, and the EPSS score of less than 1% indicates a very low probability of exploitation at the time of assessment. The vulnerability is not currently listed in CISA KEV, and no official workaround is provided. Based on the description, the most likely attack vector is remote access via the plugin’s web interface or API, where an attacker can craft requests that trigger the privilege escalation.
OpenCVE Enrichment
EUVD