SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14197

LOW · CVSS 3.8 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Fluent Support WordPress plugin prior to version 2.3.1 is vulnerable due to a lack of access controls, enabling restricted support agents to reassign tickets to any customer, regardless of their permissions. This flaw could lead to unauthorized access to sensitive customer information and disrupt ticket management. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.

CVE
CVE-2026-14197
Severity
LOW
CVSS
3.8
EPSS
0.15%
WordPress

Original NVD Description

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.