CVE-2026-14929: JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR
The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JS Help Deskto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14929?
The severity of CVE-2026-14929 is rated medium with a CVSS score of 4.3.
How do I fix CVE-2026-14929?
To fix CVE-2026-14929, update the JS Help Desk plugin to version 3.1.4 or later.
What does CVE-2026-14929 allow attackers to do?
CVE-2026-14929 allows authenticated users to overwrite the content of any ticket reply due to lack of ownership verification.
Which WordPress plugin is affected by CVE-2026-14929?
CVE-2026-14929 affects the JS Help Desk plugin for WordPress.
Who is vulnerable to CVE-2026-14929?
Any authenticated user with Subscriber permissions or higher is vulnerable to CVE-2026-14929.