VYPR

Js Help Desk

by WordPress

CVEs (32)

  • CVE-2026-48887MedJun 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in JS Help Desk <= 3.0.9 versions.

  • CVE-2026-2511HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.00

    The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being…

  • CVE-2026-32535MedMar 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3.

  • CVE-2024-43274MedNov 1, 2024
    risk 0.38cvss 5.8epss 0.00

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6.

  • CVE-2022-46840MedDec 13, 2024
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

  • CVE-2022-46842MedFeb 2, 2023
    risk 0.35cvss 5.4epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.

  • CVE-2024-31273MedJun 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3.

  • CVE-2023-23679MedJun 23, 2023
    risk 0.30cvss 4.6epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7.

  • CVE-2026-14929MedJul 31, 2026
    risk 0.28cvss 4.3epss 0.00

    The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

  • CVE-2024-13607MedFeb 4, 2025
    risk 0.21cvss 4.3epss 0.00

    The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it…

  • CVE-2026-57652MedJun 26, 2026
    risk 0.00cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions.

  • CVE-2026-56054HigJun 25, 2026
    risk 0.00cvss 7.7epss 0.00

    Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.

Page 2 of 2