Impact
The vulnerability resides in the JS Help Desk WordPress plugin versions prior to 3.1.4. The front‑end request dispatcher responsible for ticket file uploads lacks any authorization, nonce, or ownership validation. An unauthenticated user can therefore upload any file that matches the plugin’s limited allowed extensions and attach it to an existing support ticket belonging to any user. This oversight allows an attacker to add attachments to tickets belonging to any user on a WordPress site without authentication.
Affected Systems
The affected product is the JS Help Desk WordPress plugin. Versions before 3.1.4 are impacted; any installation of this plugin running those earlier versions and exposing the ticket file upload endpoint is vulnerable.
Risk and Exploitability
The lack of authentication checks for ticket file uploads creates a high‑risk vector for exploitation. An attacker can attach any file that the plugin accepts to a support ticket for any user, giving them unauthorized control over ticket attachments. The EPSS score is below 1%, indicating a very low but non‑zero probability of exploitation, and it is not listed in the CISA KEV catalog.
OpenCVE Enrichment