PatchSiren

JS Help Desk CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM JS Help Desk CVE published 2026-07-31

CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded. A low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body. This vulnerability allows unauthorized access to sensitive information, potentially exposing personally identifiable information (PII) and [truncated]

HIGH JS Help Desk CVE published 2026-07-31

CVE-2026-14930

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files and attach them to arbitrary users' support tickets. This vulnerability has a high CVSS score of 7.5 and is considered a high priority due to the potential for unauthorized file uploads. Administrators of WordPress si [truncated]

MEDIUM JS Help Desk CVE published 2026-07-31

CVE-2026-14929

The CVE record for CVE-2026-14929 was published on 2026-07-31T07:16:26.500Z and has not been modified since then. The NVD entry is currently Received. This vulnerability affects the JS Help Desk WordPress plugin, specifically versions before 3.1.4. The vulnerability allows any authenticated user with Subscriber and above privileges to overwrite the content of any support-ticket reply on the site. This cou [truncated]