Stored Cross-site Scripting Vulnerability in Octrace Studio WordPress HelpDesk Plugin
CVE-2025-22762

5.9MEDIUM

Key Information:

Summary

A security flaw exists in the Octrace Studio WordPress HelpDesk & Support Ticket System Plugin that allows for stored Cross-site Scripting (XSS) attacks. The vulnerability can be exploited by malicious actors to inject harmful scripts into web pages, potentially affecting users who access these pages through vulnerable installations. The affected versions include all prior to 1.2.7, making it crucial for users to update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

WordPress HelpDesk & Support Ticket System Plugin – Octrace Support <= 1.2.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO (Patchstack Alliance)
.