CVE-2026-14197
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
| Vendor | unknown |
| Product | fluent support |
| Published | Aug 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown fluent support
Be the first to know when new unknown vulnerabilities affecting unknown fluent support are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Fluent Support
0 < 2.3.1
References
Credits
Mustafa Ahmed WPScan