
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23977 is a Missing Authorization (Broken Access Control) vulnerability in the WPFactory Helpdesk Support Ticket System for WooCommerce WordPress plugin. It affects all versions up to and including 2.1.2, and was published on March 25, 2026, with the vulnerability originally reported on January 5, 2026. The flaw allows unauthenticated attackers to exploit incorrectly configured access control security levels, carrying a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to perform adequate authorization checks before executing privileged actions. An unauthenticated remote attacker can send crafted network requests to exploit misconfigured access control levels within the plugin, bypassing restrictions that should limit access to support ticket data and administrative functions. No user interaction is required, and the attack complexity is low, making this straightforward to exploit at scale (Patchstack).
Successful exploitation results in a high confidentiality impact, allowing unauthenticated attackers to access restricted support tickets and sensitive customer data managed through the WooCommerce helpdesk plugin. There is no direct integrity or availability impact based on the CVSS assessment, but exposure of customer support data (which may include personal information, order details, and communication history) poses significant privacy and compliance risks. The vulnerability is considered suitable for mass-exploit campaigns targeting thousands of WordPress/WooCommerce sites regardless of their size or traffic (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns against WordPress sites (Patchstack).
support-ticket-system-for-woocommerce) version 2.1.2 or earlier using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files.wp-admin/admin-ajax.php with plugin-specific action parameters, or plugin REST API routes) from unexpected IP addresses.The vendor WPFactory has released version 2.1.3 of the Helpdesk Support Ticket System for WooCommerce plugin, which patches this vulnerability. Site administrators should update to version 2.1.3 or later immediately. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the plugin is updated. If immediate updating is not possible, consider temporarily deactivating the plugin or restricting access to the WordPress site via IP allowlisting (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as part of broader WordPress plugin security coverage (Wordfence Blog). No significant additional vendor statements or notable researcher commentary beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."