Impact
VillaTheme HAPPY suffers from a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. The vulnerability grants the ability to view or manipulate tickets and related information without proper authentication, undermining confidentiality and integrity of the support system. Users without valid privileges can potentially create, edit, or delete tickets, disrupting service operations.
Affected Systems
All WordPress sites using the HAPPY help‑desk support ticket system plugin version 1.0.6 or earlier are affected. The vulnerability applies to the entire plugin as delivered by the vendor and does not rely on external components.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is through the WordPress web interface, involving authenticated or unauthenticated users who can access plugin pages without proper access checks. No additional conditions such as elevated privileges or network control are mentioned, so the flaw can potentially be leveraged by any actor with access to the site’s frontend or backend.
OpenCVE Enrichment