Impact
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress contains a flaw where the redirect‑to attribute of a shortcode is not sanitized or escaped. This allows an authenticated user with contributor‑level or higher privileges to store arbitrary scripts in the attribute. When a visitor opens a page with the injected shortcode, the hidden attribute triggers the script in compatible browsers, leading to a stored cross‑site scripting that can steal credentials or deface pages. The payload is hidden, so exploitation only occurs under specific browser conditions, limiting but not eliminating impact.
Affected Systems
All releases of the wpmanageninja Fluent Support – Helpdesk & Customer Support Ticket System plugin up to and including version 2.3.0 are affected. Any WordPress site that has installed these versions is vulnerable, regardless of the site’s configuration or the number of users.
Risk and Exploitability
The CVSS score of 6.4 marks the vulnerability as moderate severity, while the EPSS score of less than 1% indicates that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Attack requires an authenticated contributor or higher user and a viewport that interprets the hidden redirect‑to attribute. Although exploitation is not trivial, it can lead to session hijacking, defacement, or further compromise if an unsuspecting user views the page containing the payload.
OpenCVE Enrichment