CVE-2026-14197

Summary

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.

Affected Software

VendorProductVersion RangeStatus
UnknownFluent Support0 < 2.3.1affected

Weaknesses

  • CWE-639 Authorization Bypass Through User-Controlled Key

References