Junglewise Threat Intelligence

CVE-2026-48887: JS Help Desk broken access control in WordPress plugin

CVE-2026-48887 · Severity: medium · CVSS 6.5 · Published 2026-06-15

Vendors: Ahmad.

Executive brief

JS Help Desk, a WordPress plugin used for managing customer support tickets, contains a security flaw that allows unauthorized individuals to perform actions they should not be able to. An attacker could potentially modify data or disrupt support operations without needing a login. This could lead to unauthorized changes in support tickets or service availability issues.

Technical details

A broken access control vulnerability exists in the JS Help Desk plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. This allows an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 6.5, indicating it can impact the integrity and availability of the system. The issue is resolved in version 3.1.0.

Affected products

  • Ahmad JS Help Desk <= 3.0.9

Timeline

  • 2026-05-14: other: Reported by researcher Nvz
  • 2026-06-02: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats