CVE-2026-23977: WordPress Helpdesk Support Ticket System for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23977?
CVE-2026-23977 has a severity rating that indicates it poses a moderate risk due to the broken access control allowing unauthorized actions.
How do I fix CVE-2026-23977?
To fix CVE-2026-23977, update the WPFactory Helpdesk Support Ticket System for WooCommerce plugin to version 2.1.3 or later.
What versions are affected by CVE-2026-23977?
CVE-2026-23977 affects the WPFactory Helpdesk Support Ticket System for WooCommerce plugin versions up to and including 2.1.2.
What types of vulnerabilities does CVE-2026-23977 exploit?
CVE-2026-23977 exploits broken access control due to incorrect authorization settings within the plugin.
Who is responsible for fixing CVE-2026-23977?
The vendor, WPFactory, is responsible for providing updates and fixes for CVE-2026-23977.