PT-2026-66713 · WordPress · Js Help Desk
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JS Help Desk WordPress plugin versions prior to 3.1.4
Description
Upon activation, the plugin grants support-agent capabilities to the Contributor role. Additionally, it fails to perform a capability check on a user-listing handler, which allows users with Contributor-level privileges to enumerate the email addresses of all registered WordPress users.
Recommendations
Update JS Help Desk WordPress plugin to version 3.1.4 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Js Help Desk