天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-11399 WooCommerce Helpdesk 工单系统越权删除漏洞

影响低权限认证用户可越权删除他人工单回复

AI 研判

WordPress 插件 Helpdesk Support Ticket System for WooCommerce 存在不安全的直接对象引用(IDOR)漏洞。插件在删除工单回复时未对用户可控的 id 参数做归属校验,导致攻击者可删除任意用户的回复记录。该漏洞影响 2.1.6 及之前的所有版本。

影响范围

Helpdesk Support Ticket System for WooCommerce

Helpdesk Support Ticket System for WooCommerce 插件 2.1.6 及之前的所有版本。

漏洞详情

漏洞类型为不安全的直接对象引用(IDOR),成因是删除处理逻辑仅依赖用户提交的 stsw_responses 行 ID,缺少对记录归属和操作权限的校验。攻击者只需从后台页脚获取 nonce,再向删除接口提交任意回复 ID,即可删除其他用户的工单回复。

利用条件与风险

利用前提是攻击者拥有订阅者及以上级别的认证账号,并能获取有效 nonce,实战中可造成数据被恶意删除,风险中等。

修复建议

官方修复方案暂无公开信息,建议升级至 2.1.6 之后的修复版本;临时缓解措施为限制低权限账号访问工单功能,并加强对删除操作的权限与归属校验。

原始情报

The Helpdesk Support Ticket System for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.6 via the ‘id’ parameter due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary ticket responses belonging to other users by supplying any stsw_responses row ID to the deletion handler after obtaining the nonce from the admin footer.