CVE-2026-32535: WordPress JS Help Desk plugin <= 3.0.3 - Insecure Direct Object References (IDOR) vulnerability
Authorization Bypass Through User-Controlled Key vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 3.0.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32535?
CVE-2026-32535 is considered a high severity vulnerability due to its potential impact on unauthorized access to sensitive information.
How do I fix CVE-2026-32535?
To fix CVE-2026-32535, update the JoomSky JS Help Desk plugin to version 3.0.4 or later.
What systems are affected by CVE-2026-32535?
CVE-2026-32535 affects JoomSky JS Help Desk plugin versions up to and including 3.0.3.
What does CVE-2026-32535 exploit?
CVE-2026-32535 exploits an Insecure Direct Object References (IDOR) vulnerability allowing authorization bypass through user-controlled keys.
Who is the vendor related to CVE-2026-32535?
The vendor related to CVE-2026-32535 is JoomSky, which develops the JS Help Desk plugin.