What is CVE-2026-14931?
A vulnerability in the JS Help Desk WordPress plugin (versions before 3.1.4) grants a 'support-agent' capability to the Contributor role upon activation and fails to perform a capability check on a user-listing handler. This allows Contributor-level users to enumerate the email addresses of all registered WordPress users. It is recommended to update the plugin to at least version 3.1.4.
Azərbaycanca: JS Help Desk WordPress plaginində (3.1.4-dən əvvəlki versiyalar) zəiflik aşkar edilib. Aktivləşdirildikdə 'Contributor' roluna 'support-agent' icazəsi verir və istifadəçi siyahısı idarəedicisində icazə yoxlanışı aparmır, bu da həmin səviyyəli istifadəçilərə bütün qeydiyyatlı istifadəçilərin e-poçt ünvanlarını əldə etməyə imkan yaradır. Plaqini ən azı 3.1.4 versiyasına yeniləməyiniz tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of user data can be exposed through the CVE-2026-14931 vulnerability in the JS Help Desk plugin?
This vulnerability allows Contributor-level users to enumerate the email addresses of all registered WordPress users.
To which version should the JS Help Desk plugin be updated to mitigate CVE-2026-14931?
It is recommended to update the plugin to at least version 3.1.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.