Impact
The flaw is a broken access control in the WordPress Fluent Support Pro plugin version 2.3.1 and earlier, allowing a user to manipulate support tickets and related data without proper authorization. This vulnerability is classified under CWE‑862, meaning it permits users lacking sufficient privileges to perform restricted actions, potentially leading to confidentiality or integrity violations within the support system.
Affected Systems
The affected product is the WordPress plugin Fluent Support Pro from WP ManageNinja LLC. Versions up to and including 2.3.1 are impacted; any release prior to 2.3.2 remains vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS is not available, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Attackers who can log in as a standard subscriber or obtain a subscriber‑level account may exploit the missing authorization checks to access or modify tickets, thereby gaining unauthorized control over support interactions.
OpenCVE Enrichment