Stored Cross-site Scripting Vulnerability in Octrace Studio WordPress HelpDesk Plugin
CVE-2025-22762
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 15 January 2025
What is CVE-2025-22762?
A security flaw exists in the Octrace Studio WordPress HelpDesk & Support Ticket System Plugin that allows for stored Cross-site Scripting (XSS) attacks. The vulnerability can be exploited by malicious actors to inject harmful scripts into web pages, potentially affecting users who access these pages through vulnerable installations. The affected versions include all prior to 1.2.7, making it crucial for users to update to the latest version to mitigate risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WordPress HelpDesk & Support Ticket System Plugin β Octrace Support <= 1.2.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved