Executive brief
Fluent Support is a WordPress plugin used for managing customer support tickets and help desks. A security vulnerability in versions 2.3.0 and earlier allows users with 'Contributor' level access to inject malicious scripts into the website. If an administrator or other site visitor views the affected content, these scripts could be used to redirect users to malicious sites, steal session information, or perform unauthorized actions on behalf of the victim.
Technical details
A Stored Cross-Site Scripting (XSS) vulnerability exists in the WPManageNinja Fluent Support plugin for WordPress (versions <= 2.3.0). The flaw is due to improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with 'Contributor' level privileges can inject malicious JavaScript payloads that are stored on the server. The attack requires a victim (typically an administrator) to interact with the affected page for the script to execute in their browser context. This can lead to session hijacking or unauthorized administrative actions. The issue is resolved in version 2.3.1.
Affected products
- WPManageNinja Fluent Support <= 2.3.0
Timeline
- 2026-07-09: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-07-22: advisory: Patchstack advisory published
- 2026-07-23: advisory: NVD published CVE-2026-65470
- 2026-07-23: patched: Version 2.3.1 identified as unaffected version