Impact
The VillaTheme HAPPY help‑desk plugin contains a missing authorization flaw (CWE‑862) that allows exploitation of incorrectly configured access‑control security levels. This means that an attacker who can interact with the plugin may bypass the intended restrictions, potentially gaining unauthorized access to protected administrative functions or data within the plugin.
Affected Systems
WordPress sites that have the HAPPY plugin (happy‑helpdesk‑support‑ticket‑system) from VillaTheme with a version of 1.0.8 or earlier are affected.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1 % suggests that widespread exploitation is unlikely at present. This vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit the flaw by accessing the plugin’s administrative interface or any authenticated session that has permission to manage the plugin, thereby bypassing the intended access controls.
OpenCVE Enrichment