Impact
The vulnerability permits an attacker to bypass authorization controls by manipulating a user‑controlled key parameter, enabling access to resources such as support tickets that the attacker should not see. This is an IDOR flaw, allowing a malicious user to read or modify data intended for only authorized personnel, potentially exposing sensitive customer information and disrupting service integrity.
Affected Systems
The issue affects the AhmadJS Help Desk plugin, named JS Help Desk, on WordPress installations. Versions up to and including 4.0.0 are vulnerable; any installation using 4.0.0 or earlier is at risk.
Risk and Exploitability
The CVSS score is 4.3, which indicates a medium risk severity. No EPSS score is available, so current exploit probability is unknown. The vulnerability is not listed on the CISA KEV catalog. Attackers can exploit the flaw remotely, for example by sending crafted URLs with a manipulated ticket ID, provided the WordPress site allows external access to the plugin’s administrative endpoints. The correct configuration would restrict access, but the current default configuration is permissive.
OpenCVE Enrichment