CVE-2026-14931: JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure
Published Jul 31, 2026
·Updated
The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capability check on a user-listing handler, allowing Contributor-level users to enumerate the email addresses of all registered WordPress users.
Affected Software
1 affected component
WordPress JS Help Desk<3.1.4
Event History
Jul 31, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14931?
The severity of CVE-2026-14931 is rated as risk 29.
2
How does CVE-2026-14931 affect WordPress users?
CVE-2026-14931 allows Contributor-level users to disclose the email addresses of all registered WordPress users.
3
How do I fix CVE-2026-14931?
To fix CVE-2026-14931, update the JS Help Desk plugin to version 3.1.4 or later.
4
What capability is improperly assigned in CVE-2026-14931?
CVE-2026-14931 improperly assigns the support-agent capability to the Contributor role upon activation.
5
Which versions of JS Help Desk are impacted by CVE-2026-14931?
JS Help Desk versions prior to 3.1.4 are impacted by CVE-2026-14931.