CVE-2026-15209: JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR
The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15209?
CVE-2026-15209 has a risk rating of 54, indicating a moderate severity level.
How do I fix CVE-2026-15209?
To fix CVE-2026-15209, update the JS Help Desk WordPress plugin to version 3.1.5 or later.
What type of vulnerability is CVE-2026-15209?
CVE-2026-15209 is an IDOR (Insecure Direct Object Reference) vulnerability affecting the JS Help Desk plugin.
What data is exposed in CVE-2026-15209?
CVE-2026-15209 allows low-privileged authenticated users to access another user's support ticket data, including PII and message bodies.
Who is affected by CVE-2026-15209?
CVE-2026-15209 affects users of the JS Help Desk WordPress plugin before version 3.1.5.