plugin

Js Support Ticket Vulnerabilities

56 known security issues reported for the Js Support Ticket WordPress plugin. Most recent disclosed Aug 4, 2026.

8 critical 10 high 17 medium

Running Js Support Ticket on your site? Check whether your installed version is affected.

Scan your site free

JS Help Desk – AI-Powered Support & Ticketing System < 3.1.4 - Authenticated (Subscriber+) Information Exposure

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to 3.1.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive user or configuration data.

CVSS:
4.3
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Aug 4, 2026

CVE-2026-14928 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System < 3.1.4 - Unauthenticated Arbitrary Media Upload

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to arbitrary media uploads in all versions up to 3.1.4 (exclusive). This makes it possible for unauthenticated attackers to upload arbitrary media files.

CVSS:
5.3
Affected:
up to 3.1.4
Fixed in:
3.1.4
Disclosed:
Jul 13, 2026

CVE-2026-14930 on NVD →

JS Help Desk <= 3.1.3 - Authenticated (Contributor+) User Email Disclosure

medium

The JS Help Desk plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.1.3. This is due to missing capability check in the getuserlistajax function, allowing any authenticated user to retrieve user records including email addresses. This makes it possible for authentic...

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jul 13, 2026

CVE-2026-14931 on NVD →

JS Help Desk <= 3.1.3 - Missing Authorization to Authenticated (Subscriber+) Ticket Reply Modification

medium

The JS Help Desk plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 3.1.3. This is due to missing authorization check in the editReply() function allowing any authenticated user to edit replies without verifying ownership or role. This makes it possible for authenticated attacke...

CVSS:
4.3
Affected:
up to 3.1.3
Fixed in:
3.1.4
Disclosed:
Jul 13, 2026

CVE-2026-14929 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Cross-User Support Ticket Disclosure

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.1.4. This is due to missing authorization checks on the ticket edit action, allowing any authenticated user to access tickets without verifying ownership or...

CVSS:
4.3
Affected:
up to 3.1.4
Fixed in:
3.1.5
Disclosed:
Jul 13, 2026

CVE-2026-15209 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 - Unauthenticated Insecure Direct Object Reference

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.0 due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.1.0
Fixed in:
3.1.1
Disclosed:
Jun 26, 2026

CVE-2026-57652 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary fil...

CVSS:
8.8
Affected:
up to 3.1.1
Fixed in:
3.1.2
Disclosed:
Jun 25, 2026

CVE-2026-56054 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Unauthenticated SQL Injection

high

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attack...

CVSS:
7.5
Affected:
up to 3.0.9
Fixed in:
3.1.0
Disclosed:
Jun 2, 2026

CVE-2026-48886 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Missing Authorization

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.9. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.0.9
Fixed in:
3.1.0
Disclosed:
Jun 2, 2026

CVE-2026-48887 on NVD →

JS Help Desk - WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability

critical

WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter vulnerability

CVSS:
9.3
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Mar 30, 2026

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter

high

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to the user-supplied `multiformid` value being passed to `esc_sql()` without enclosing th...

CVSS:
7.5
Affected:
up to 3.0.4
Fixed in:
3.0.5
Disclosed:
Mar 25, 2026

CVE-2026-2511 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.3 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to p...

CVSS:
4.3
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Mar 23, 2026

CVE-2026-32535 on NVD →

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) SQL Injection

medium

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attacker...

CVSS:
6.5
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
Mar 20, 2026

CVE-2026-32534 on NVD →

JS Help Desk - WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie vulnerability

critical

WordPress JS Help Desk - AI-Powered Support & Ticketing System plugin 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie vulnerability

CVSS:
9.3
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Mar 4, 2026

JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie

high

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of suff...

CVSS:
7.5
Affected:
up to 2.8.2
Fixed in:
2.8.3
Disclosed:
Mar 3, 2026

CVE-2023-7337 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] <= 3.0.1 (unfixed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows Blind SQL Injection.This issue affects JS Help Desk: from n/a through <= 3.0.1.

Affected:
up to 3.0.1
Fix:
No patched version reported
Disclosed:
Feb 20, 2026

CVE-2026-24959 on NVD →

JS Help Desk <= 3.0.1 - Authenticated (Subscriber+) SQL Injection

medium

The JS Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber-level access and abov...

CVSS:
6.5
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Feb 11, 2026

CVE-2026-24959 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.9.3

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk allows SQL Injection. This issue affects JS Help Desk: from n/a through 2.9.2.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Apr 1, 2025

CVE-2025-30886 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.9.2

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.1.

Affected:
up to 2.9.2
Fixed in:
2.9.2
Disclosed:
Apr 1, 2025

CVE-2025-30882 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.9.3

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk allows PHP Local File Inclusion. This issue affects JS Help Desk: from n/a through 2.9.2.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Apr 1, 2025

CVE-2025-30901 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.9.3

unknown

[en] Missing Authorization vulnerability in JoomSky JS Help Desk allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JS Help Desk: from n/a through 2.9.2.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Apr 1, 2025

CVE-2025-30880 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.9.3

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JoomSky JS Help Desk allows Path Traversal. This issue affects JS Help Desk: from n/a through 2.9.2.

Affected:
up to 2.9.3
Fixed in:
2.9.3
Disclosed:
Apr 1, 2025

CVE-2025-30878 on NVD →

JS Help Desk <= 2.9.2 - Unauthenticated Local File Inclusion

critical

The JS Help Desk plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access control...

CVSS:
9.8
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Mar 27, 2025

CVE-2025-30901 on NVD →

JS Help Desk <= 2.9.2 - Unauthenticated Arbitrary File Deletion

critical

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which...

CVSS:
9.1
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Mar 27, 2025

CVE-2025-30878 on NVD →

JS Help Desk <= 2.9.1 - Unauthenticated Arbitrary File Download

high

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.9.1. This makes it possible for unauthenticated attackers to downlod the contents of arbitrary files on the server, which can contain sensitive information.

CVSS:
7.5
Affected:
up to 2.9.1
Fixed in:
2.9.2
Disclosed:
Mar 27, 2025

CVE-2025-30882 on NVD →

JS Help Desk <= 2.9.2 - Unauthenticated SQL Injection

high

The JS Help Desk plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 2.9.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries in...

CVSS:
7.5
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Mar 27, 2025

CVE-2025-30886 on NVD →

JS Help Desk <= 2.9.2 - Missing Authorization

medium

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.9.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.9.2
Fixed in:
2.9.3
Disclosed:
Mar 27, 2025

CVE-2025-30880 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.9

unknown

[en] The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in th...

Affected:
up to 2.8.9
Fixed in:
2.8.9
Disclosed:
Feb 13, 2025

CVE-2024-13606 on NVD →

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

high

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp...

CVSS:
7.5
Affected:
up to 2.8.8
Fixed in:
2.8.9
Disclosed:
Feb 12, 2025

CVE-2024-13606 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.9

unknown

[en] The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with...

Affected:
up to 2.8.9
Fixed in:
2.8.9
Disclosed:
Feb 4, 2025

CVE-2024-13607 on NVD →

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subs...

CVSS:
4.3
Affected:
up to 2.8.8
Fixed in:
2.8.9
Disclosed:
Feb 3, 2025

CVE-2024-13607 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.2

unknown

[en] Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Dec 13, 2024

CVE-2022-46838 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.2

unknown

[en] Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Dec 13, 2024

CVE-2022-46840 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.8

unknown

[en] Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Stored XSS.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.7.

Affected:
up to 2.8.8
Fixed in:
2.8.8
Disclosed:
Nov 9, 2024

CVE-2024-51670 on NVD →

JS Help Desk – Best Help Desk & Support Plugin <= 2.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to injec...

CVSS:
4.4
Affected:
up to 2.8.7
Fixed in:
2.8.8
Disclosed:
Nov 1, 2024

CVE-2024-51670 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.7

unknown

[en] Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.6.

Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Nov 1, 2024

CVE-2024-43274 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.7

unknown

[en] The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the...

Affected:
up to 2.8.7
Fixed in:
2.8.7
Disclosed:
Aug 13, 2024

CVE-2024-7094 on NVD →

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution

critical

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style...

CVSS:
9.8
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Aug 12, 2024

CVE-2024-7094 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.4

unknown

[en] Missing Authorization vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.3.

Affected:
up to 2.8.4
Fixed in:
2.8.4
Disclosed:
Jun 9, 2024

CVE-2024-31273 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.8

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin allows Using Malicious Files.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.7.

Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
May 17, 2024

CVE-2023-25444 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Apr 17, 2024

CVE-2022-47151 on NVD →

JS Help Desk – Best Help Desk & Support Plugin <= 2.8.3 - Missing Authorization

medium

The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.8.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.8.3
Fixed in:
2.8.4
Disclosed:
Apr 5, 2024

CVE-2024-31273 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.2

unknown

[en] Unrestricted Upload of File with Dangerous Type vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.7.1.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Jan 5, 2024

CVE-2022-46839 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.8.2

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.

Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Dec 28, 2023

CVE-2023-50839 on NVD →

JS Help Desk <= 2.8.1 - Unauthenticated SQL Injection via email and trackingid

critical

The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to SQL Injection via the ‘email' and 'trackingid' parameters in all versions up to 2.8.2 (exclusive) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes...

CVSS:
9.8
Affected:
up to 2.8.2
Fixed in:
2.8.2
Disclosed:
Dec 21, 2023

CVE-2023-50839 on NVD →

JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Administrator+) Arbitrary File Upload

high

The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.7. This makes it possible for administrators to upload arbitrary files on the affected site's server which may make remote code execution possible.

CVSS:
7.2
Affected:
up to 2.7.7
Fixed in:
2.7.8
Disclosed:
Aug 17, 2023

CVE-2023-25444 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.8

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JS Help Desk: from n/a through 2.7.7.

Affected:
up to 2.7.8
Fixed in:
2.7.8
Disclosed:
Jun 23, 2023

CVE-2023-23679 on NVD →

JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Subscriber+) Insecure Direct Object Reference

medium

The "JS Help Desk – Best Help Desk & Support Plugin" plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.7.7 via the 'email' parameter due to missing validation on a user controlled key. This can allow authenticated attackers, with subscriber-level access and above...

CVSS:
6.3
Affected:
up to 2.7.7
Fixed in:
2.7.8
Disclosed:
Jun 20, 2023

CVE-2023-23679 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.7.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in JS Help Desk plugin <= 2.7.1 versions.

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Feb 2, 2023

CVE-2022-46842 on NVD →

JS Help Desk <= 2.7.1 - Unauthenticated Arbitrary File Upload

critical

The JS Help Desk plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 2.7.1. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.

CVSS:
9.8
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jan 27, 2023

CVE-2022-46839 on NVD →

JS Help Desk <= 2.7.1 - Missing Authorization to Plugin Settings Update

critical

The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.7.1. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
9.1
Affected:
2.7.1 – 2.7.1
Fixed in:
2.7.2
Disclosed:
Jan 27, 2023

CVE-2022-46838 on NVD →

JS Help Desk <= 2.7.1 - Unauthenticated SQL Injection

high

The JS Help Desk plugin for WordPress is vulnerable to generic SQL Injection via an unknown parameter in versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to...

CVSS:
8.6
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jan 27, 2023

CVE-2022-47151 on NVD →

JS Help Desk <= 2.7.1 - Missing Authorization

medium

The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.7.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function intended for higher-privi...

CVSS:
6.3
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jan 27, 2023

CVE-2022-46840 on NVD →

JS Help Desk <= 2.7.1 - Cross-Site Request Forgery

medium

The JS Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.7.1. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted they can trick...

CVSS:
5.4
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jan 27, 2023

CVE-2022-46842 on NVD →

JS Help Desk – AI-Powered Support &amp; Ticketing System [js-support-ticket] < 2.0.6

unknown

[en] The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.

Affected:
up to 2.0.6
Fixed in:
2.0.6
Disclosed:
Aug 27, 2019

CVE-2018-21002 on NVD →

JS Help Desk – Best Help Desk & Support Plugin <= 2.0.5 - Cross-Site Request Forgery

high

The JS Help Desk plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.5. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise unauthorized access to administrative privileges via a forged request gr...

CVSS:
8.8
Affected:
up to 2.0.5
Fixed in:
2.0.6
Disclosed:
Jun 25, 2018

CVE-2018-21002 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database