CVE-2026-15209
Vulnerability Description
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
JS Help Desk
Discussion (0)
Add Comment
No comments yet. Be the first!