{"id":"CVE-2026-14197","title":"The Fluent Support  WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, includi…","summary":"The Fluent Support  WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, includi…","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14197","references":[{"url":"https://wpscan.com/vulnerability/cd488221-6efd-42a0-badc-315c60ec0b99/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00152,"epssPercentile":0.04777,"ingestedAt":"2026-08-02T01:16:32.556Z","slug":"CVE-2026-14197","body":"## Overview\n\nThe Fluent Support  WordPress plugin before 2.3.1 does not perform a per-ticket access check before reassigning a ticket's customer, allowing a restricted support agent to change the assigned customer of any ticket in the system, including tickets outside their granted scope.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}