Junglewise Threat Intelligence

CVE-2026-56054: Ahmad JS Help Desk arbitrary file deletion via path traversal

CVE-2026-56054 · Severity: high · CVSS 7.7 · Published 2026-06-25

Vendors: Ahmad.

Executive brief

JS Help Desk is a WordPress plugin used to manage customer support tickets. A security vulnerability in versions 3.1.1 and earlier allows users with basic 'Subscriber' accounts to delete arbitrary files on the web server. This could lead to a complete site failure or the removal of critical security configurations, potentially allowing attackers to break the website or bypass other security measures.

Technical details

The JS Help Desk (js-support-ticket) plugin for WordPress, up to and including version 3.1.1, is vulnerable to arbitrary file deletion. This issue stems from improper limitation of a pathname to a restricted directory (CWE-22), commonly known as path traversal. An authenticated attacker with Subscriber-level privileges can exploit this flaw via network requests to delete sensitive files on the server. Successful exploitation can lead to a denial-of-service condition by deleting core WordPress files or configuration files. The vulnerability is addressed in version 3.1.2.

Affected products

  • Ahmad JS Help Desk (js-support-ticket) <= 3.1.1

Timeline

  • 2026-06-14: other: Reported by researcher daroo
  • 2026-06-25: disclosed: Vulnerability published by Patchstack
  • 2026-06-25: patched: Version 3.1.2 released to address the issue

References