Impact
The JS Help Desk WordPress plugin fails to verify that the user requesting a ticket reply update actually owns that reply. This IDOR flaw allows any authenticated user with at least Subscriber privileges to overwrite the contents of any support‑ticket reply on the site, potentially fabricating responses or altering evidence. The attacker cannot execute code or read arbitrary data; the primary risk is the integrity of support interactions and the possibility of defacing supported content.
Affected Systems
WordPress sites that install the JS Help Desk plugin version earlier than 3.1.4. The affected vendor/product is listed as Unknown:JS Help Desk, and the vulnerability applies to any installations that have not applied the 3.1.4 update. No specific host or environment information is provided beyond the plugin version constraint.
Risk and Exploitability
The vulnerability is exploitable by any logged‑in user from the Subscriber role upwards, meaning the attack vector is local to authenticated users. EPSS data is unavailable and the issue is not in the CISA KEV catalog, but the lack of ownership checks indicates a high integrity impact. While no public exploit is documented, the combination of broad access and critical data modification warrants frequent monitoring, and the CVSS score is not supplied; however the potential damage is significant enough to treat the risk as high.
OpenCVE Enrichment