What is CVE-2026-15209?
The JS Help Desk WordPress plugin before version 3.1.5 fails to verify ticket ownership, allowing a low-privileged authenticated user to supply another user's ticket ID and read its contents, including PII and message body. This leads to unauthorized information disclosure. Updating the plugin to version 3.1.5 or higher is strongly recommended.
Azərbaycanca: JS Help Desk (WordPress plugin) 3.1.5 versiyasından əvvəl istifadəçi ticket sahibliyini yoxlamır, beləliklə aşağı səlahiyyətli autentifikasiya olunmuş istifadəçi başqasının ticket ID-sini təqdim edərək onun şəxsi məlumatlarını və mesaj məzmununu oxuya bilər. Bu, şəxsi məlumatların sızmasına səbəb olur. Plugin-i dərhal 3.1.5 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the JS Help Desk plugin are affected by CVE-2026-15209?
All versions of the JS Help Desk plugin before 3.1.5 are affected by this vulnerability. The flaw allows a low-privileged authenticated user to supply another user's ticket ID and read its contents, including PII and message body.
How can the vulnerability CVE-2026-15209 be mitigated?
To mitigate the vulnerability, it is strongly recommended to immediately update the JS Help Desk plugin to version 3.1.5 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.