Executive brief
The HAPPY Helpdesk Support Ticket System plugin for WordPress contains a security flaw that fails to properly verify user permissions. This allows unauthorized individuals to perform actions that should be restricted to higher-privileged users, potentially disrupting support operations or modifying ticket data. Organizations using this plugin should update to the latest version to prevent unauthorized access to helpdesk functions.
Technical details
A missing authorization vulnerability (CWE-862) exists in the VillaTheme HAPPY plugin (also known as Happy Helpdesk Support Ticket System) for WordPress in versions up to and including 1.0.10. The flaw stems from incorrectly configured access control security levels, which fail to validate the authorization of a user before executing certain functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the affected site, leading to the execution of actions that should require higher privileges. This can result in unauthorized data modification or service disruption. The issue is resolved in version 1.0.11.
Affected products
- VillaTheme HAPPY (Helpdesk Support Ticket System) n/a through 1.0.10
Timeline
- 2026-02-04: other: Reported by Nabil Irawan
- 2026-04-16: advisory: Initial disclosure by Patchstack
- 2026-05-21: disclosed: CVE published to NVD
- 2026-04-16: patched: Version 1.0.11 released