Description
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass via IDOR
Action: Patch
AI Analysis

Impact

The vulnerability permits an attacker to bypass authorization controls by manipulating a user‑controlled key parameter, enabling access to resources such as support tickets that the attacker should not see. This is an IDOR flaw, allowing a malicious user to read or modify data intended for only authorized personnel, potentially exposing sensitive customer information and disrupting service integrity.

Affected Systems

The issue affects the AhmadJS Help Desk plugin, named JS Help Desk, on WordPress installations. Versions up to and including 4.0.0 are vulnerable; any installation using 4.0.0 or earlier is at risk.

Risk and Exploitability

The CVSS score is 4.3, which indicates a medium risk severity. No EPSS score is available, so current exploit probability is unknown. The vulnerability is not listed on the CISA KEV catalog. Attackers can exploit the flaw remotely, for example by sending crafted URLs with a manipulated ticket ID, provided the WordPress site allows external access to the plugin’s administrative endpoints. The correct configuration would restrict access, but the current default configuration is permissive.

Generated by OpenCVE AI on October 5, 2026 at 10:28 UTC.

Remediation

Vendor Solution

Update the WordPress JS Help Desk plugin to the latest available version (at least 5.0.0).


OpenCVE Recommended Actions

  • Update the JS Help Desk plugin to the latest version, at least 5.0.0, to eliminate the IDOR flaw.
  • Verify that role‑based access restrictions are correctly configured in WordPress so that only authorized users can view or edit support tickets.
  • If an immediate update is not possible, restrict external access to the plugin’s administrative URLs via web server rules or a firewall to prevent unauthorized users from reaching the vulnerable endpoints.
  • If the plugin is not required for operation, consider temporarily disabling or uninstalling it until a patch is applied.

Generated by OpenCVE AI on October 5, 2026 at 10:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.
Title WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-05T08:39:07.062Z

Reserved: 2026-09-30T00:15:58.645Z

Link: CVE-2026-103078

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T09:17:06.137

Modified: 2026-10-05T09:17:06.137

Link: CVE-2026-103078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T10:30:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key