SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14929

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The JS Help Desk plugin for WordPress prior to version 3.1.4 is vulnerable due to a lack of ownership verification for support-ticket replies, enabling any authenticated user with Subscriber privileges or higher to overwrite existing replies. This could lead to misinformation or disruption in support communications, potentially impacting user trust and support operations. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-14929
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The JS Help Desk WordPress plugin before 3.1.4 does not verify ownership of the targeted reply before updating it, allowing any authenticated user (Subscriber and above) to overwrite the content of any support-ticket reply on the site.