What the vulnerability does
01Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish WooCommerce Support Ticket System woocommerce-support-ticket-system allows Path Traversal.This issue affects WooCommerce Support Ticket System: from n/a through < 18.5.
Explanation of Vulnerability in Simple Terms
02Summary
The WooCommerce Support Ticket System contains a path traversal vulnerability that allows an unauthenticated attacker to disrupt service availability. By crafting malicious file path requests over the network, an attacker can cause the application to become unavailable. No user interaction is required. The vulnerability affects versions before 18.5.
What an attacker can do
03Attacker Capabilities
Make the site unavailable by sending specially crafted requests that exploit path traversal.
Potential impact on your site
04Site Impact
Your site may become unavailable or unresponsive due to denial-of-service attacks.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 29, 2026
Record updated