Description
Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.10.4.
Published: 2026-01-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Privilege Escalation
Action: Apply Patch Immediately
AI Analysis

Impact

A missing authorization check in the Fluent Support WordPress plugin allows an attacker to bypass intended access restrictions. The flaw arises from incorrectly configured security levels, enabling the exploitation of privilege boundaries. Attackers could potentially gain unauthorized access to support tickets, modify content, or view sensitive information that should be protected by user roles, thereby compromising confidentiality or integrity of support data.

Affected Systems

Affected systems include WordPress sites that use the Shahjahan Jewel Fluent Support plugin from any unreleased build through version 1.10.4. The vulnerability applies to all installations of the plugin that have not been updated beyond this release. No specific operating system or WordPress version is mentioned in the advisory, so all WordPress environments that run the vulnerable plugin are impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate level of severity. The EPSS score of less than 1% suggests that, while the vulnerability exists, the likelihood of exploitation in the wild is currently low. The plugin does not appear in the CISA KEV catalog, which aligns with its low EPSS. Based on the description, the attack vector is inferred to involve authenticated users who gain access to the plugin’s administrative functionality but are granted broader privileges than intended. An attacker with such access could exploit the broken access control to read or modify support tickets, thereby violating confidentiality, integrity, or availability of support data.

Generated by OpenCVE AI on April 28, 2026 at 18:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Fluent Support plugin to the latest version that includes the fix for the broken access control issue.
  • After updating, review and tighten the plugin’s role permissions to ensure only authorized users can access support ticket functionality.
  • If an update is not yet available, remove or disable the plugin’s administrative endpoints, or enforce stricter WordPress role restrictions to block unauthorized access to support features.

Generated by OpenCVE AI on April 28, 2026 at 18:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 09 Jan 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 08 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Jan 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 08 Jan 2026 09:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.10.4.
Title WordPress Fluent Support plugin <= 1.10.4 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:24.155Z

Reserved: 2025-12-15T09:59:49.437Z

Link: CVE-2025-67926

cve-icon Vulnrichment

Updated: 2026-01-08T14:54:50.514Z

cve-icon NVD

Status : Deferred

Published: 2026-01-08T10:15:51.620

Modified: 2026-04-27T18:16:49.730

Link: CVE-2025-67926

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-28T18:30:37Z

Weaknesses