
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14581 is an authorization bypass vulnerability in the HAPPY – Helpdesk Support Ticket System plugin for WordPress, caused by a missing capability check on the submit_form_reply AJAX action. All plugin versions up to and including 1.0.9 are affected. The vulnerability was published on December 13, 2025, and was assigned by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing authorization check (CWE-862) on the submit_form_reply AJAX action within the plugin's happy-replies.php file (line 585). An authenticated attacker with Subscriber-level access or higher can manipulate the happy_topic_id POST parameter in an AJAX request to target any support ticket, bypassing ownership and assignment checks entirely. No complex preconditions are required beyond having a valid WordPress account on the affected site (Wordfence, WordPress Trac).
Successful exploitation allows authenticated attackers to inject unauthorized replies into any support ticket on the affected WordPress site, compromising ticket integrity and potentially exposing sensitive information contained in those tickets to unauthorized parties. The impact is limited to integrity (low) with no direct confidentiality or availability impact per the CVSS scoring, though injected replies could be used for social engineering or to mislead support staff and customers (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.028% (0.000280), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only a low-privileged authenticated account (Subscriber level), making it accessible to any registered user on a vulnerable WordPress site (Wordfence, Red Hat CVE).
happy_topic_id values for tickets not owned by or assigned to the attacker./wp-admin/admin-ajax.php) with the action submit_form_reply and a manipulated happy_topic_id parameter pointing to the target ticket, along with the desired reply content./wp-admin/admin-ajax.php with action=submit_form_reply and happy_topic_id values not associated with the authenticated user's tickets.admin-ajax.php with submit_form_reply from low-privileged user accounts; unexpected reply submissions on tickets not owned by the submitting user.WordPress site administrators should update the HAPPY – Helpdesk Support Ticket System plugin to version 1.1.0 or later, which includes the fix for the missing capability check. The patch was committed to the WordPress plugin repository (changeset 3417847). Until an update can be applied, consider disabling the plugin or restricting site registration to prevent untrusted users from obtaining Subscriber-level accounts (Wordfence, WordPress Trac).
The vulnerability was reported and assigned by Wordfence, which published the initial advisory. Coverage has been limited to automated vulnerability tracking platforms such as VulDB, Vulners, and CIRCL's vulnerability lookup service, with no notable researcher commentary or significant media coverage identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."