VYPR
High severity8.5NVD Advisory· Published Feb 20, 2026· Updated Apr 15, 2026

CVE-2026-24959

CVE-2026-24959

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind SQL injection in JS Help Desk plugin (≤3.0.1) allows unauthenticated attackers to extract database contents via crafted input.

Vulnerability

Overview

The JS Help Desk plugin for WordPress (js-support-ticket) versions up to and including 3.0.1 contain a blind SQL injection vulnerability classified as Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'). This flaw enables blind SQL injection attacks, where an attacker can inject malicious SQL queries through user-supplied input that is not properly sanitized before being used in database queries [1].

Exploitation

Details

The vulnerability is exploitable without authentication, making it accessible to any remote attacker. The vulnerability is considered highly dangerous and is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their size or popularity [1]. The attack surface is broad because the plugin is widely deployed on many sites.

Impact

Successful exploitation allows an attacker to directly interact with the underlying database. This could lead to data theft, including sensitive information such as user credentials, personal data, or other stored content. The CVSS v3 score of 8.5 (High) reflects the severe potential for confidentiality impact [1].

Mitigation

The vendor has released version 3.0.2 which resolves the vulnerability. Users are strongly advised to update immediately. For those unable to update, Patchstack offers a mitigation rule available to block attacks until the patch is applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.