WordPress security changelog
UNKNOWN CVE-2026-14197 Received

Restricted Fluent Support agents can reassign customers on any ticket

Fluent Support before 2.3.1 changes a ticket's customer without checking whether the requesting support agent may access that ticket. A restricted agent can select any ticket, including one outside their granted scope, and assign a different customer, corrupting ticket ownership and potentially exposing the ticket through normal customer access. The record does not disclose the endpoint or action, ticket and customer parameters, authorization callback or update function.

CVE / CNA score Pending The CVE record has not published a CNA CVSS assessment.
NVD score Pending NVD has not published its own CVSS assessment.
Component
Fluent Support
Plugin slug
fluent-support
Affected
< 2.3.1
Safe version
2.3.1
Published
Aug 01, 2026
Weakness
Not assigned

This CVE was published Aug 01, 2026 and is one of 10 known issues for this plugin.

Update, patch or deactivate.

Update Fluent Support to 2.3.1 or later. Review restricted-agent activity and customer changes on out-of-scope tickets, restore correct assignments, inspect whether reassignment exposed ticket content, and notify affected customers when warranted.

A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.

Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.

Technical description

The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.

Primary and upstream sources