CVE-2024-44011 HIGH

CVE-2024-44011: WordPress WP Ticket Ultra plugin <= 1.0.5 - Local File Inclusion vulnerability

Vendor Expresstech Systems
Product WP Ticket Ultra Help Desk & Support Plugin
Weakness CWE-22 · Path traversal
Published October 5, 2024
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a through <= 1.0.5.

Explanation of Vulnerability in Simple Terms

02Summary

WP Ticket Ultra Help Desk & Support Plugin versions 1.0.5 and earlier contain a path traversal vulnerability that allows an attacker to read or modify files on the server. The vulnerability requires the attacker to trick a user into visiting a malicious link. An attacker can access sensitive files outside the intended directory, potentially exposing database credentials, configuration files, or other confidential data.

What an attacker can do

03Attacker Capabilities

Read or modify files on the server outside the intended directory by crafting a malicious URL.

Potential impact on your site

04Site Impact

Attackers can access sensitive files like wp-config.php, database backups, or user data without logging in.

Conditions required to exploit

05Prerequisites

No authentication required, but the victim must click a malicious link or visit an attacker-controlled page.

Key dates

06Disclosure timeline

October 5, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE