Stored Cross-Site Scripting in Fluent Support Plugin for WordPress
CVE-2026-15665
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-15665?
The Fluent Support plugin for WordPress contains a vulnerability that allows for Stored Cross-Site Scripting (XSS) through the 'redirect-to' shortcode attribute. This issue arises from inadequate input sanitization and output escaping, exposing the plugin to potential exploits by authenticated attackers with contributor-level access or higher. When an attacker successfully exploits this vulnerability, they can inject malicious web scripts into pages viewed by users, leading to the execution of these scripts under certain conditions. The payload is crafted to activate in specific browsers when particular access keys are triggered, making the attack somewhat situational but still a significant risk.
Affected Version(s)
Fluent Support β Helpdesk & Customer Support Ticket System 0 <= 2.3.0