The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded. A low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. This vulnerability allows unauthorized access to sensitive information, potentially exposing personally identifiable information (PII) and [truncated]
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files and attach them to arbitrary users' support tickets. This vulnerability has a high CVSS score of 7.5 and is considered a high priority due to the potential for unauthorized file uploads. Administrators of WordPress si [truncated]
The CVE record for CVE-2026-14929 was published on 2026-07-31T07:16:26.500Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects the JS Help Desk WordPress plugin, specifically versions before 3.1.4. The vulnerability allows any authenticated user with Subscriber and above privileges to overwrite the content of any support-ticket reply on the site. This cou [truncated]