What is CVE-2026-14930?
The JS Help Desk WordPress plugin before 3.1.4 lacks authorization, nonce, and ownership checks on a front-end request dispatcher. This vulnerability allows unauthenticated users to upload files with limited allowed extensions and attach them to tickets. Updating to version 3.1.4 or later is strongly recommended.
Azərbaycanca: JS Help Desk WordPress plaginində 3.1.4 versiyasından əvvəl avtorizasiya, nonce və sahiblik yoxlaması aparılmır. Bu zəiflik autentifikasiya olunmamış istifadəçilərə front-end sorğu dispetçeri vasitəsilə məhdud fayl uzantıları ilə fayl yükləməyə və onları biletlərə qoşmağa imkan yaradır. Plaginin ən son 3.1.4 versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which version of the JS Help Desk plugin is affected by CVE-2026-14930?
This vulnerability affects all versions of the JS Help Desk WordPress plugin before 3.1.4.
What can an attacker do by exploiting this vulnerability?
An unauthenticated user can upload files with limited allowed extensions via a front-end request dispatcher and attach them to tickets.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.