Live Vulnerability Intelligence
Threat Database
Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.
Js Help Desk - Cross-Site Request Forgery (CSRF) (CVE-2026-14930)
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
CVE-2026-14930
Js Help Desk - Broken Access Control (CVE-2026-15209)
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
CVE-2026-15209
Js Help Desk - Broken Access Control (CVE-2026-14931)
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
CVE-2026-14931
Js Help Desk - Security Vulnerability (CVE-2026-14928)
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
CVE-2026-14928
Js Help Desk - Security Vulnerability (CVE-2026-14929)
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
CVE-2026-14929
JS Help Desk - Security Vulnerability (CVE-2026-56054)
Subscriber Arbitrary File Deletion in JS Help Desk
CVE-2026-56054
JS Help Desk - SQL Injection (CVE-2026-48886)
Unauthenticated SQL Injection in JS Help Desk
CVE-2026-48886
JS Help Desk - Broken Access Control (CVE-2026-48887)
Unauthenticated Broken Access Control in JS Help Desk
CVE-2026-48887
JS Help Desk - SQL Injection (CVE-2026-2511)
The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing the result in quotes in the SQL query, rendering the escaping ineffective against payloads that do not contain quote characters. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract…
CVE-2026-2511
Js Help Desk - Information Disclosure (CVE-2024-13606)
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/jssupportticketdata directory which can contain file attachments included in support tickets.
CVE-2024-13606