Executive brief
JS Help Desk, a WordPress plugin used for managing customer support tickets, contains a security flaw that allows unauthorized individuals to perform actions they should not be able to. An attacker could potentially modify data or disrupt support operations without needing a login. This could lead to unauthorized changes in support tickets or service availability issues.
Technical details
A broken access control vulnerability exists in the JS Help Desk plugin for WordPress due to missing authorization checks (CWE-862) in certain functions. This allows an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. The vulnerability has a CVSS score of 6.5, indicating it can impact the integrity and availability of the system. The issue is resolved in version 3.1.0.
Affected products
- Ahmad JS Help Desk <= 3.0.9
Timeline
- 2026-05-14: other: Reported by researcher Nvz
- 2026-06-02: advisory: Patchstack advisory published
- 2026-06-15: disclosed: NVD publication date