What is CVE-2026-14197?
This vulnerability exists in the "Fluent Support" WordPress plugin versions prior to 2.3.1. Due to a missing per-ticket access check during customer reassignment, a restricted support agent can change the assigned customer of any ticket in the system, including those outside their scope. Immediate update to version 2.3.1 or higher is strongly recommended.
Azərbaycanca: Bu zəiflik "Fluent Support" WordPress plugin-inin 2.3.1-dən əvvəlki versiyalarında aşkar edilib. Plugin hər bilet üçün fərdi giriş yoxlaması (per-ticket access check) aparmadığı üçün, məhdud icazələrə malik support agenti sistemdəki istənilən biletin (öz səlahiyyət dairəsindən kənarda olanlar da daxil) müştərisini dəyişdirə bilər. Plugin-i dərhal 2.3.1 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What does the CVE-2026-14197 vulnerability allow a restricted support agent to do in the Fluent Support plugin?
The vulnerability allows a restricted support agent to change the assigned customer of any ticket in the system, including those outside their scope.
To what version should Fluent Support be updated to fix CVE-2026-14197?
It is strongly recommended to immediately update the Fluent Support plugin to version 2.3.1 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.