Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Saruul

#55703of 57,584
4.3Total CVSS
Vulnerabilities · 1
PT-2026-104505
4.3
2026-10-03
WordPress · Helpdesk Support Ticket System For Woocommerce · CVE-2026-11399
**Name of the Vulnerable Software and Affected Versions** Helpdesk Support Ticket System for WooCommerce versions prior to 2.1.7 **Description** An Insecure Direct Object Reference (IDOR) exists due to missing validation on a user-controlled key. Authenticated attackers with subscriber-level access or higher can delete arbitrary ticket responses belonging to other users. This is achieved by supplying a `stsw responses` row ID to the deletion handler after obtaining a nonce from the admin footer via the `id` parameter. **Recommendations** Update the plugin to a version later than 2.1.6. Avoid using the `id` parameter in the deletion handler until the update is applied.