WordPress Plugin Vulnerabilities
JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
Description
The plugin does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the plugin's inert allowed extensions) and attach them to arbitrary users' support tickets.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-07-13 (about 1 month ago)
Added
2026-07-13 (about 1 month ago)
Last Updated
2026-07-13 (about 1 month ago)