medium · CVSS v3 4.3
CVE-2026-11399
The WooCommerce Helpdesk Support Ticket System plugin for WordPress is vulnerable to an insecure direct object reference that allows authent
Overview
The WooCommerce Helpdesk Support Ticket System plugin for WordPress is vulnerable to an insecure direct object reference that allows authenticated users with subscriber-level access to delete other users' ticket responses. The flaw exists in all versions up to 2.1.6 and requires only the ability to supply a ticket response ID and a valid nonce. This can lead to loss of customer support data and potential disruption of service.
Description
The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.
Impact
Confidentiality: Ticket responses may be deleted, compromising data integrity. Integrity: Deletion of responses undermines support records. Availability: Potential disruption of support workflow. Impact: Site administrators, support staff, and customers relying on accurate ticket histories.
Remediation
Update the plugin to version 2.1.7 or later where the ID validation is fixed. If an update is not immediately possible, restrict subscriber-level users from accessing the ticket deletion endpoint by adjusting role capabilities or using a security plugin to block the 'id' parameter. Additionally, monitor logs for abnormal deletion activity and enforce stricter nonce validation.
Risk context
Medium severity (CVSS 4.3). No EPSS data available. The vulnerability can be exploited by any authenticated subscriber, making it a moderate risk that should be addressed promptly but not considered critical.
Affected products
- WooCommerce Helpdesk Support Ticket System
Scores
- Severity
- medium
- CVSS v2
- 4
- CVSS v3
- 4.3
- CVSS v4
- —
- EPSS
- —