Description
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
Published: 2026-10-03
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of ticket responses by authenticated subscribers
Action: Apply Patch
AI Analysis

Impact

The Helpdesk Support Ticket System for WooCommerce plugin allows authenticated users with subscriber-level access to delete any ticket response. Missing validation on the 'id' parameter permits arbitrary deletion of stsw_responses entries by leaking nonces from the admin footer. This vulnerability can lead to loss of user data and potentially compromise data integrity, but does not grant code execution or widespread system compromise. The documented CVSS score of 4.3 reflects a moderate impact to confidentiality and integrity of support data.

Affected Systems

All versions of the Helpdesk Support Ticket System for WooCommerce plugin produced by WPCodeFactory up to and including 2.1.6. No specific sub‑versions are listed beyond the maximum 2.1.6, so any installation of the plugin at that level or below is vulnerable.

Risk and Exploitability

The exploit requires an authenticated session and the ability to obtain an admin‑generated nonce, so the attack vector is limited to legitimate users of the site with Subscriber or higher privileges. The lack of EPSS data and absence from the CISA KEV catalog indicate no current widespread exploitation, but the moderate CVSS score still warrants attention. Until a patch is deployed, attackers could delete arbitrary support responses, degrading user trust and support integrity.

Generated by OpenCVE AI on October 3, 2026 at 06:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Helpdesk Support Ticket System for WooCommerce plugin to the latest available version that includes the fix for ID validation.
  • Verify that the deletion endpoint now checks both the user's capability and the submitted 'id' against the owner of the ticket response before performing the delete action.
  • If an immediate upgrade is not possible, restrict the deletion feature to administrators only by using a role‑management plugin or custom code that removes the delete capability from subscribers and lower roles.

Generated by OpenCVE AI on October 3, 2026 at 06:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 03 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
Title Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-03T15:42:45.864Z

Reserved: 2026-06-05T16:31:55.166Z

Link: CVE-2026-11399

cve-icon Vulnrichment

Updated: 2026-10-03T15:39:33.232Z

cve-icon NVD

Status : Received

Published: 2026-10-03T06:16:42.230

Modified: 2026-10-03T16:16:35.447

Link: CVE-2026-11399

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-03T06:45:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key