CyberRota Analysis
AI-GeneratedThe JS Help Desk WordPress plugin prior to version 3.1.4 is vulnerable due to a lack of authorization checks, enabling unauthenticated users to upload files with specific extensions and associate them with any user's support tickets. This could lead to unauthorized access to sensitive information and potential exploitation of the system. WordPress site administrators using this plugin should prioritize updating to version 3.1.4 or later to mitigate the risk.
Original NVD Description
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.