← Zurück zur CVE-Suche

CVE-2026-14929

JS Help Desk

Beschreibung

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.

CVSS 4.3EPSS 0.152%Risiko 0.44
Quelle öffnen
Veröffentlicht
2026-07-31 07:16:26
Betroffene Versionen
<3.1.4
Typ
Webanwendung
Zuletzt geändert
2026-07-31 14:16:47
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N