---
id: CVE-2026-11399
title: >-
  The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is
  vulnerable to Insecure Direct Object Reference in all versions up to, and
  including, 2.1.6 via the 'id' parameter due to missing validation on a user
  controlled k…
summary: >-
  The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is
  vulnerable to Insecure Direct Object Reference in all versions up to, and
  including, 2.1.6 via the 'id' parameter due to missing validation on a user
  controlled k…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-639
vendor: wpcodefactory
product: Helpdesk Support Ticket System for WooCommerce
affected:
  - helpdesk_support_ticket_system_for_woocommerce <= 2.1.6
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T06:16:42.230'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-11399'
references:
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&old=3713322%40support-ticket-system-for-woocommerce&new=3713322%40support-ticket-system-for-woocommerce
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0715b5bf-8123-4e75-95e1-4b7d39f37d64?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T06:39:57.562Z'
---

## Overview

The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
