PT-2026-66712 · WordPress · Js Help Desk
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JS Help Desk WordPress plugin versions prior to 3.1.4
Description
An issue exists in the front-end request dispatcher where the software fails to perform authorization, nonce, or ownership checks. This allows unauthenticated users to upload files, restricted to the plugin's allowed extensions, and attach them to support tickets belonging to arbitrary users. A nonce is a unique token used to prevent replay attacks by ensuring that a request is intentional and not forged.
Recommendations
Update JS Help Desk WordPress plugin to version 3.1.4 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Js Help Desk