What is CVE-2026-14928?
CVE-2026-14928: The JS Help Desk WordPress plugin before version 3.1.4 lacks authorization and ownership checks in its ticket search handler, allowing any authenticated user (e.g., Subscriber) to read the subject and full message body of other users' support tickets. Immediate update to version 3.1.4 or later is required.
Azərbaycanca: CVE-2026-14928: "JS Help Desk" WordPress plaqini 3.1.4 versiyasından əvvəlki versiyalarda dəstək biletlərinin axtarış funksiyasında avtorizasiya və sahiblik yoxlanışı aparmır. Bu zəiflik autentifikasiya olunmuş istənilən istifadəçiyə (məsələn, Subscriber rolu) digər istifadəçilərin bilet mövzularını və tam mesaj məzmununu oxumağa imkan verir. Plaqini dərhal 3.1.4 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which users can exploit the CVE-2026-14928 vulnerability in the JS Help Desk plugin?
This vulnerability can be exploited by any authenticated user, including those with low-level permissions such as the Subscriber role.
What data can be exposed due to the CVE-2026-14928 vulnerability in the JS Help Desk plugin?
The vulnerability allows reading the subject and full message body of other users' support tickets.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.