Back to CVE List

CVE-2026-15209

Vulnerability Description

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
JS Help Desk

External References

Discussion (0)

Add Comment

No comments yet. Be the first!