CyberRota Analysis
AI-GeneratedThe JS Help Desk plugin for WordPress prior to version 3.1.4 is vulnerable due to a lack of authorization checks, enabling any authenticated user (including Subscribers) to access and read the subject and full message body of all users' support tickets. This exposure of sensitive support ticket information poses a privacy risk and could lead to unauthorized disclosure of user data. WordPress administrators and site owners using this plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce-gated search handler, allowing any authenticated user (Subscriber and above) to read the subject and full message body of every other user's support tickets.