SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14930

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The JS Help Desk WordPress plugin prior to version 3.1.4 is vulnerable due to a lack of authorization checks, enabling unauthenticated users to upload files with specific extensions and associate them with any user's support tickets. This could lead to unauthorized access to sensitive information and potential exploitation of the system. WordPress site administrators using this plugin should prioritize updating to version 3.1.4 or later to mitigate the risk.

CVE
CVE-2026-14930
Severity
HIGH
CVSS
7.5
EPSS
0.24%
WordPress

Original NVD Description

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.