SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14931

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The JS Help Desk plugin for WordPress prior to version 3.1.4 improperly elevates the Contributor role by granting it support-agent capabilities, enabling these users to list the email addresses of all registered users without proper authorization checks. This vulnerability poses a risk of user data exposure, which could lead to targeted phishing attacks or other malicious activities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-14931
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.