CVE-2026-103079: WordPress JS Help Desk plugin <= 4.0.0 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through 4.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JS Help Desk pluginto a version that resolves this vulnerability.Fixed in 5.0.0
Event History
Frequently Asked Questions
What level of access does an attacker need?
The attacker needs low-level privileges and can exploit the issue remotely over the network. No user interaction is required.
What is the expected impact of successful exploitation?
Successful exploitation can result in limited confidentiality and integrity impact. No availability impact is indicated.
How can I identify installations that need review?
Review systems running the Ahmad JS Help Desk plugin and identify deployments at version 4.0.0 or earlier. The affected range is listed as through version 4.0.0.