WordPress Plugin Vulnerabilities

JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload

Description

The plugin does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the plugin's inert allowed extensions) and attach them to arbitrary users' support tickets.

Proof of Concept

Affects Plugins

Fixed in 3.1.4

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 1 month ago)
Added
2026-07-13 (about 1 month ago)
Last Updated
2026-07-13 (about 1 month ago)

Other