CVE-2026-11399 PUBLISHED

Helpdesk Support Ticket System for WooCommerce <= 2.1.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Ticket Response Deletion via 'id' Parameter

Assigner: Wordfence
Reserved: 05.06.2026 Published: 03.10.2026 Updated: 03.10.2026

The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 4.3

Product Status

Vendor wpcodefactory
Product Helpdesk Support Ticket System for WooCommerce
Versions Default: unaffected
  • affected from 0 to 2.1.6 (incl.)

Credits

  • Saruul finder

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE