CVE-2026-14197: Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Fluent Support WordPress pluginto a version that resolves this vulnerability.Fixed in 2.3.1