Fluent Support – Helpdesk & Customer Support Ticket System < 2.3.1 - Authenticated (Custom role+) Insecure Direct Object Reference
medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to 2.3.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with custom role-level access and above, to perform an una...
- CVSS:
- 4.3
- Affected:
- up to 2.3.1
- Fixed in:
- 2.3.1
- Disclosed:
- Aug 1, 2026
CVE-2026-14197 on NVD →
Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute
medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute in all versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- CVSS:
- 6.4
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 23, 2026
CVE-2026-15665 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above...
- CVSS:
- 6.4
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jul 22, 2026
CVE-2026-65470 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] <= 1.10.4 (unfixed)
unknown
[en] Missing Authorization vulnerability in Shahjahan Jewel Fluent Support fluent-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through <= 1.10.4.
- Affected:
- up to 1.10.4
- Fix:
- No patched version reported
- Disclosed:
- Jan 8, 2026
CVE-2025-67926 on NVD →
Fluent Support <= 1.10.4 - Missing Authorization
medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.10.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an...
- CVSS:
- 4.3
- Affected:
- up to 1.10.4
- Fixed in:
- 1.10.5
- Disclosed:
- Jan 5, 2026
CVE-2025-67926 on NVD →
Fluent Support <= 1.9.1 - Cross-Site Request Forgery
medium
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized...
- CVSS:
- 4.3
- Affected:
- up to 1.9.1
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 22, 2025
CVE-2025-57885 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.9.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Shahjahan Jewel Fluent Support allows Cross Site Request Forgery. This issue affects Fluent Support: from n/a through 1.9.1.
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Aug 22, 2025
CVE-2025-57885 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.8.6
unknown
[en] The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the 'fluent-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the...
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Mar 1, 2025
CVE-2024-13568 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System <= 1.8.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
high
The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.8.5 via the 'fluent-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-...
- CVSS:
- 7.5
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.6
- Disclosed:
- Feb 28, 2025
CVE-2024-13568 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.8.1
unknown
[en] Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8.0.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Nov 1, 2024
CVE-2024-47302 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.8.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support allows SQL Injection.This issue affects Fluent Support: from n/a through 1.8.0.
- Affected:
- up to 1.8.1
- Fixed in:
- 1.8.1
- Disclosed:
- Oct 17, 2024
CVE-2024-47304 on NVD →
Fluent Support <= 1.8.0 - Authenticated (Subscriber+) SQL Injection
medium
The Fluent Support plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.8.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and a...
- CVSS:
- 6.5
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Sep 25, 2024
CVE-2024-47304 on NVD →
Fluent Support <= 1.8.0 - Insufficient Authorization on Email Verification
medium
The Fluent Support plugin for WordPress is vulnerable to unauthorized email verification due to insufficient validation on the sendSignupEmailVerificationHtml ()function in versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to verify emails that do not belong to themselves.
- CVSS:
- 5.3
- Affected:
- up to 1.8.0
- Fixed in:
- 1.8.1
- Disclosed:
- Sep 25, 2024
CVE-2024-47302 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.7.7
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPManageNinja LLC Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin.This issue affects Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin: from n/a through 1.7.6.
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Dec 31, 2023
CVE-2023-51547 on NVD →
Fluent Support <= 1.7.6 - Authenticated(Administrator+) SQL Injection
medium
The Fluent Support – WordPress Helpdesk and Customer Support Ticket Plugin plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in all versions up to 1.7.7 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This...
- CVSS:
- 6.6
- Affected:
- up to 1.7.7
- Fixed in:
- 1.7.7
- Disclosed:
- Dec 27, 2023
CVE-2023-51547 on NVD →
Fluent Support – Helpdesk & Customer Support Ticket System [fluent-support] < 1.5.8
unknown
[en] The Fluent Support WordPress plugin before 1.5.8 does not properly sanitise, validate and escape various parameters before using them in an SQL statement, leading to an SQL Injection vulnerability exploitable by high privilege users
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.8
- Disclosed:
- Aug 29, 2022
CVE-2022-2559 on NVD →
Fluent Support <= 1.5.7 - Authenticated (Administrator+) SQL Injection
high
The Fluent Support plugin for WordPress is vulnerable to SQL Injection via an unknown parameter in versions up to, and including, 1.5.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append...
- CVSS:
- 7.2
- Affected:
- up to 1.5.7
- Fixed in:
- 1.5.8
- Disclosed:
- Aug 2, 2022
CVE-2022-2559 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database