Restricted Fluent Support agents can reassign customers on any ticket
Fluent Support before 2.3.1 changes a ticket's customer without checking whether the requesting support agent may access that ticket. A restricted agent can select any ticket, including one outside their granted scope, and assign a different customer, corrupting ticket ownership and potentially exposing the ticket through normal customer access. The record does not disclose the endpoint or action, ticket and customer parameters, authorization callback or update function.
- Component
- Fluent Support
- Plugin slug
fluent-support- Affected
- < 2.3.1
- Safe version
2.3.1- Published
- Aug 01, 2026
- Weakness
- Not assigned
This CVE was published Aug 01, 2026 and is one of 10 known issues for this plugin.
Update, patch or deactivate.
Update Fluent Support to 2.3.1 or later. Review restricted-agent activity and customer changes on out-of-scope tickets, restore correct assignments, inspect whether reassignment exposed ticket content, and notify affected customers when warranted.
A safe version is available, so updating to that version or later is the preferred remediation. If an immediate update is not practical, consider a targeted application patch or temporarily restricting the affected functionality.
Deactivate only when warranted by your risk profile, or when advised by your hosting provider in the limited circumstances where the vulnerability cannot otherwise be mitigated. If you’re unsure which action is appropriate, contact Fused or your hosting provider for guidance.
Technical description
The Fluent Support WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.