SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14928

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The JS Help Desk plugin for WordPress prior to version 3.1.4 is vulnerable due to a lack of authorization checks, enabling any authenticated user (including Subscribers) to access and read the subject and full message body of all users' support tickets. This exposure of sensitive support ticket information poses a privacy risk and could lead to unauthorized disclosure of user data. WordPress administrators and site owners using this plugin should prioritize updating to the latest version to mitigate this vulnerability.

CVE
CVE-2026-14928
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.