Impact
The vulnerability affects WP Support Plus Responsive Ticket System versions 9.1.2 and earlier. Because the plugin does not sign or verify the guest‑session cookie it issues, an attacker can forge that cookie with any chosen email address. By presenting the forged cookie to the site, the server treats the victim of the email address as the authenticated ticket owner, allowing the attacker to view, reply to, and close the owner’s support tickets. This flaw exposes confidential ticket information and permits arbitrary ticket manipulation without needing any credentials.
Affected Systems
Any WordPress site running WP Support Plus Responsive Ticket System on version 9.1.2 or lower is affected. The flaw arises because the plugin does not sign or verify the guest‑session cookie it issues to unauthenticated users, allowing attackers to forge that cookie and impersonate any ticket owner.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers only need to know the ticket owner’s email address. Based on the description, it is inferred that the email address may be publicly visible, allowing an attacker to forge a guest‑session cookie and impersonate the owner. With a crafted HTTP request containing the forged cookie, a determined attacker can read, reply to, and close tickets without valid credentials.
OpenCVE Enrichment