sales@hackhalt.com

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total10
Critical1
High4
Medium5
Reset
Showing 1-10 of 10 records
Threat Entry Updated 2026-08-26

Js Help Desk - Cross-Site Request Forgery (CSRF) (CVE-2026-14930)

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.

PLUGIN Js Help Desk

CVE-2026-14930

HIGH CVSS 7.5 2026-07-31
Threat Entry Updated 2026-08-26

Js Help Desk - Broken Access Control (CVE-2026-15209)

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

PLUGIN Js Help Desk

CVE-2026-15209

MEDIUM CVSS 6.5 2026-07-31
Threat Entry Updated 2026-08-26

Js Help Desk - Broken Access Control (CVE-2026-14931)

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.

PLUGIN Js Help Desk

CVE-2026-14931

MEDIUM CVSS 6.5 2026-07-31
Threat Entry Updated 2026-08-26

Js Help Desk - Security Vulnerability (CVE-2026-14928)

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.

PLUGIN Js Help Desk

CVE-2026-14928

MEDIUM CVSS 6.5 2026-07-31
Threat Entry Updated 2026-08-26

Js Help Desk - Security Vulnerability (CVE-2026-14929)

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

PLUGIN Js Help Desk

CVE-2026-14929

MEDIUM CVSS 4.3 2026-07-31
Threat Entry Updated 2026-06-17

JS Help Desk - SQL Injection (CVE-2026-2511)

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing the result in quotes in the SQL query, rendering the escaping ineffective against payloads that do not contain quote characters. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract…

PLUGIN JS Help Desk

CVE-2026-2511

HIGH CVSS 7.5 2026-03-26
Threat Entry Updated 2025-02-18

Js Help Desk - Information Disclosure (CVE-2024-13606)

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/jssupportticketdata directory which can contain file attachments included in support tickets.

PLUGIN Js Help Desk

CVE-2024-13606

HIGH CVSS 7.5 2025-02-13