CVE-2026-56054: WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability
Published Jun 25, 2026
·Updated
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
Affected Software
1 affected component
WordPress JS Help Desk<=3.1.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress JS Help Desk pluginto a version that resolves this vulnerability.Fixed in 3.1.2
Event History
Jun 25, 2026
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-56054?
The severity of CVE-2026-56054 is high with a score of 7.7.
2
What type of vulnerability is identified in CVE-2026-56054?
CVE-2026-56054 is an Arbitrary File Deletion vulnerability due to Path Traversal in the JS Help Desk plugin.
3
Who can exploit the vulnerability in CVE-2026-56054?
The vulnerability in CVE-2026-56054 can be exploited by subscribers of the WordPress JS Help Desk plugin.
4
What versions of the WordPress JS Help Desk are affected by CVE-2026-56054?
CVE-2026-56054 affects WordPress JS Help Desk plugin versions up to and including 3.1.1.
5
How do I fix CVE-2026-56054?
To fix CVE-2026-56054, update the WordPress JS Help Desk plugin to a version beyond 3.1.1.