WordPress Plugin Vulnerabilities

JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR

Description

The plugin does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

Proof of Concept

Affects Plugins

Fixed in 3.1.4

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Yaswanth Reddy Sunkara
Submitter
Yaswanth Reddy Sunkara
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 13 days ago)
Added
2026-07-13 (about 13 days ago)
Last Updated
2026-07-13 (about 13 days ago)

Other