Impact
The Fluent Support WordPress plugin, versions earlier than 2.3.1, contains an IDOR flaw that bypasses per-ticket access checks when reassigning a ticket’s customer. An attacker who is a support agent on the site can change the customer assigned to any ticket, even those outside the agent’s authorized scope. This flaw allows a restricted user to hijack ownership of support tickets, potentially exposing customer data and undermining the platform’s trust model. The weakness is an improper access‑control violation, commonly classified as CWE‑639.
Affected Systems
Fluent Support WordPress plugin versions prior to 2.3.1 are affected. The vendor is listed as Unknown:Fluent Support within the CNA data. Exact version numbers are not provided beyond the 2.3.1 threshold.
Risk and Exploitability
The CVSS score is 3.8, but the EPSS score indicates a very low exploitation probability (<1%). The vulnerability is not included in the CISA KEV catalog, suggesting no known widespread attacks yet. However, the attack vector is likely through the plugin’s ticket reassignment user interface, and the exposed privilege escalation can be leveraged by any authenticated support agent with access to the ticket management page. Security teams should consider the potential for abuse in environments where support agents have administrative privileges.
OpenCVE Enrichment