CVE-2026-14928
JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
| Vendor | unknown |
| Product | js help desk |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown js help desk
Be the first to know when new unknown vulnerabilities affecting unknown js help desk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / JS Help Desk
0 < 3.1.4
References
Credits
Muni Nitish Kumar Yaddala WPScan