CVE-2026-11589Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users to upload files containing malicious JavaScript (such as HTML or SVG) to a publicly accessible location, leading to Stored Cross-Site Scripting attacks against site users and administrators.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-30: 2Technical Details · 2026-06-30: 206-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ADK Cyber@ADKCyber
    Disclosure

    CVE-2026-11589 (CVSS 8.8): WP Support Plus Responsive Ticket System plugin <=9.1.2 contains a high-severity flaw. Review and update any affected WordPress sites. https://nvd.nist.gov/vuln/deta… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/8q8G5bVBBM

    Post summary

    The tweet announces a high‑severity flaw (CVSS 8.8) in the WP Support Plus Responsive Ticket System plugin (<=9.1.2) and urges site owners to review and update, but provides no PoC, exploit, or evidence of active use.

    0000047
    92 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-11589 Stored Cross-Site Scripting via Unauthenticated File Upload in WP Support Plus 9.1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-11589

    Post summary

    A new stored XSS vulnerability was disclosed in WP Support Plus 9.1.2, triggered by unauthenticated file uploads; no PoC, exploit, or patch details are provided.

    0000082
    4.1K followersView on X

Explore more