Unrated severityNVD Advisory· Published Aug 1, 2026
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVE-2026-14197
Description
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/cd488221-6efd-42a0-badc-315c60ec0b99/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.