CVE-2026-14930
JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
| Vendor | unknown |
| Product | js help desk |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown js help desk
Be the first to know when new unknown vulnerabilities affecting unknown js help desk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / JS Help Desk
0 < 3.1.4
References
Credits
Shivamani Vastrala WPScan