CyberRota Analysis
AI-GeneratedThe JS Help Desk plugin for WordPress prior to version 3.1.4 improperly elevates the Contributor role by granting it support-agent capabilities, enabling these users to list the email addresses of all registered users without proper authorization checks. This vulnerability poses a risk of user data exposure, which could lead to targeted phishing attacks or other malicious activities. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.