Impact
The vulnerability is a missing authorization flaw in the VillaTheme HAPPY WordPress plugin, allowing attackers to bypass intended access restrictions. By exploiting incorrect configuration of security levels, an attacker could view or modify tickets and related customer data, potentially compromising confidentiality and integrity of support interactions. The flaw is identified as CWE-862.
Affected Systems
All WordPress sites that have installed the HAPPY plugin up to and including version 1.0.9 are affected. Any deployment that uses the default or misconfigured access control settings for this plugin is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the short term, and the vulnerability is not yet listed in the CISA KEV catalog. The typical attack vector is remote; the flaw can be triggered through the plugin’s web interface by an authenticated or unauthenticated user depending on the current configuration.
OpenCVE Enrichment