CVE-2026-14928

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14928

Mitre link : CVE-2026-14928

CVE.ORG link : CVE-2026-14928


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor