Impact
The Guest Support WordPress plugin has a missing capability check on the deleteMassTickets function, allowing unauthenticated users to delete any support ticket. This flaw results in loss of customer support data and undermines the integrity of the ticketing system. The vulnerability is categorized as a missing authorization weakness (CWE‑862).
Affected Systems
WordPress sites running the Guest Support plugin from rcatheme, including all releases up to and including version 1.2.2. No other products are known to be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1 % shows a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by invoking the deleteMassTickets AJAX endpoint without authentication, thereby deleting arbitrary tickets.
OpenCVE Enrichment
EUVD