VYPR
Medium severity6.5NVD Advisory· Published Jul 31, 2026· Updated Aug 26, 2026

CVE-2026-14928

CVE-2026-14928

Description

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

1