Description
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
Published: 2026-07-31
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JS Help Desk WordPress plugin, prior to version 3.1.4, assigns the support‑agent capability to the Contributor role upon activation and omits a capability check when handling user listings. This allows any Contributor‑level user to request a list of all registered WordPress user email addresses, exposing private contact information and enabling phishing or social‑engineering attacks. The flaw breaches user confidentiality by revealing email addresses.

Affected Systems

The affected product is the JS Help Desk WordPress plugin provided by Unknown:JS Help Desk. All releases earlier than version 3.1.4 are vulnerable; users of these older versions should consider them compromised until the plugin is updated.

Risk and Exploitability

The EPSS score of <1% indicates a low but non‑zero exploitation probability. The likely attack vector requires the attacker to hold a Contributor role on the site, implying internal access; this is inferred because a Contributor user is needed to trigger the user‑listing handler. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits, but the impact of email disclosure can be significant for targeted phishing campaigns. The CVSS score of 6.5 reflects a moderate overall risk in environments where email addresses are sensitive.

Generated by OpenCVE AI on August 4, 2026 at 22:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JS Help Desk plugin to version 3.1.4 or later.
  • If upgrading immediately is not possible, remove the support‑agent capability from the Contributor role or temporarily disable the plugin until a patch is applied.
  • Implement a least‑privilege configuration for WordPress roles, ensuring that Contributor users do not receive elevated capabilities beyond what is necessary for their tasks.

Generated by OpenCVE AI on August 4, 2026 at 22:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 31 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Fri, 31 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Description The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
Title JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-31T19:47:50.635Z

Reserved: 2026-07-07T09:19:10.202Z

Link: CVE-2026-14931

cve-icon Vulnrichment

Updated: 2026-07-31T19:47:45.692Z

cve-icon NVD

Status : Received

Published: 2026-07-31T07:16:26.720

Modified: 2026-07-31T20:16:47.637

Link: CVE-2026-14931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:45:03Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor