What is CVE-2026-14929?
CVE-2026-14929 is a vulnerability in the JS Help Desk WordPress plugin before version 3.1.4. It fails to verify ownership of the targeted reply before updating it, allowing any authenticated user, such as a Subscriber, to overwrite any support ticket reply. Site administrators should immediately update the plugin to the latest version.
Azərbaycanca: CVE-2026-14929, JS Help Desk WordPress plaginində 3.1.4 versiyasından əvvəlki versiyalarda aşkar edilmiş zəiflikdir. Bu zəiflik autentifikasiya olunmuş hər hansı bir istifadəçiyə (Subscriber və yuxarı rollar) sahiblik yoxlanışı olmadan dəstək biletlərinin cavablarını dəyişdirməyə imkan verir. Sayt inzibatçıları dərhal plaqini ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which versions of the JS Help Desk plugin are affected by CVE-2026-14929?
This vulnerability affects all versions of the JS Help Desk plugin prior to version 3.1.4.
What is the minimum user role required to exploit CVE-2026-14929?
Any authenticated user, including those with a Subscriber role, can exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.