Impact
The Helpdesk Support Ticket System for WooCommerce plugin allows authenticated users with subscriber-level access to delete any ticket response. Missing validation on the 'id' parameter permits arbitrary deletion of stsw_responses entries by leaking nonces from the admin footer. This vulnerability can lead to loss of user data and potentially compromise data integrity, but does not grant code execution or widespread system compromise. The documented CVSS score of 4.3 reflects a moderate impact to confidentiality and integrity of support data.
Affected Systems
All versions of the Helpdesk Support Ticket System for WooCommerce plugin produced by WPCodeFactory up to and including 2.1.6. No specific sub‑versions are listed beyond the maximum 2.1.6, so any installation of the plugin at that level or below is vulnerable.
Risk and Exploitability
The exploit requires an authenticated session and the ability to obtain an admin‑generated nonce, so the attack vector is limited to legitimate users of the site with Subscriber or higher privileges. The lack of EPSS data and absence from the CISA KEV catalog indicate no current widespread exploitation, but the moderate CVSS score still warrants attention. Until a patch is deployed, attackers could delete arbitrary support responses, degrading user trust and support integrity.
OpenCVE Enrichment