Impact
The JS Help Desk WordPress plugin versions prior to 3.1.4 lack authorization or ownership checks when serving support‑ticket content through a nonce‑protected search handler. This flaw permits any authenticated user with Subscriber level privileges or higher to retrieve the subject line and full message body of other users’ tickets, effectively exposing confidential support‑ticket data. The weakness corresponds to unsecured disclosure of sensitive information (CWE‑200), leading to a confidentiality breach that could reveal personal or business information.
Affected Systems
This vulnerability affects installations of the JS Help Desk plugin in WordPress deployments that are running any version earlier than 3.1.4. All sites that use the plugin for support ticket management and allow users to authenticate as Subscribers or higher roles are potentially impacted. The plugin vendor for this product has not issued a formal product fix with a CNA‑assigned name, but attacks apply to all instances of the compromised code.
Risk and Exploitability
Because the vulnerability requires only authentication, a large number of users across affected sites could leverage it without additional privileges. With a CVSS score of 6.5, the vulnerability presents a moderate severity level. The EPSS score of <1% indicates low exploitation likelihood, and the flaw is not listed in CISA’s KEV catalog, but the potential for widespread confidentiality exposure still warrants attention. Attackers could trigger the flaw by sending a properly formed request to the checkAIReplyTicketsBySubject endpoint while authenticating to the site, thereby extracting all visible ticket data. The lack of a public exploit does not preclude its use, and the ease of discovery and use of the endpoint makes it a realistic target.
OpenCVE Enrichment