Impact
Improper Control of Generation of Code (CWE-94) in the VillaTheme HAPPY happy‑helpdesk‑support‑ticket‑system plugin allows remote code inclusion. An attacker can craft input that the plugin interprets as executable code, enabling the execution of arbitrary commands on the affected WordPress site. This flaw provides full system compromise, including confidentiality, integrity, and availability loss.
Affected Systems
The vulnerability affects the VillaTheme HAPPY happy‑helpdesk‑support‑ticket‑system plugin for versions from the initial release through 1.0.7. No specific patch version is listed, but any release beyond 1.0.7 is presumed to contain the fix.
Risk and Exploitability
The CVSS score is 10, indicating critical severity. The EPSS score is below 1 %, suggesting that known exploitation attempts are rare at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through web requests processed by the plugin, assuming the site allows unauthenticated or low‑privilege access to the plugin’s functionality. Without an immediate fix, a determined attacker could achieve complete control of the affected WordPress instance.
OpenCVE Enrichment