VYPR
Unrated severityNVD Advisory· Published Aug 1, 2026

Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR

CVE-2026-14197

Description

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.