Stored Cross-Site Scripting in Fluent Support Plugin for WordPress
CVE-2026-15665

6.4MEDIUM

What is CVE-2026-15665?

The Fluent Support plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting (XSS) through the 'redirect-to' shortcode attribute. This issue arises from inadequate input sanitization and output escaping, exposing the plugin to potential exploits by authenticated attackers with contributor-level access or higher. When an attacker successfully exploits this vulnerability, they can inject malicious web scripts into pages viewed by users, leading to the execution of these scripts under certain conditions. The payload is crafted to activate in specific browsers when particular access keys are triggered, making the attack somewhat situational but still a significant risk.

Affected Version(s)

Fluent Support – Helpdesk & Customer Support Ticket System 0 <= 2.3.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.