CyberRota Analysis
AI-GeneratedThe JS Help Desk plugin for WordPress prior to version 3.1.4 is vulnerable due to a lack of ownership verification for support-ticket replies, enabling any authenticated user with Subscriber privileges or higher to overwrite existing replies. This could lead to misinformation or disruption in support communications, potentially impacting user trust and support operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.