CVE-2026-14930: JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/js-help-deskto a version that resolves this vulnerability.Fixed in 3.1.4 - Compensating control
Restrict access to the WordPress site’s front-end (and/or the JS Help Desk endpoints) so that unauthenticated users cannot reach the vulnerable front-end request dispatcher until the plugin is upgraded to 3.1.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14930?
CVE-2026-14930 has a high severity rating of 7.5 on the CVSS scale.
How do I fix CVE-2026-14930?
To fix CVE-2026-14930, update the JS Help Desk WordPress plugin to version 3.1.4 or later.
What type of vulnerability is CVE-2026-14930?
CVE-2026-14930 is an unauthenticated arbitrary file attachment upload vulnerability affecting the JS Help Desk plugin.
What could be the impact of CVE-2026-14930?
The impact of CVE-2026-14930 allows unauthenticated users to upload files, which could lead to malicious file execution or information disclosure.
What versions of the JS Help Desk plugin are affected by CVE-2026-14930?
CVE-2026-14930 affects all versions of the JS Help Desk WordPress plugin prior to 3.1.4.