CVE-2026-56054
Deferred Deferred - Pending Action
Subscriber Arbitrary File Deletion in JS Help Desk

Publication date: 2026-06-25

Last updated on: 2026-06-25

Assigner: Patchstack

Description
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-25
Last Modified
2026-06-25
Generated
2026-06-25
AI Q&A
2026-06-25
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The provided information does not specify how the arbitrary file deletion vulnerability in JS Help Desk Plugin affects compliance with common standards and regulations such as GDPR or HIPAA.

Executive Summary

CVE-2026-56054 is an Arbitrary File Deletion vulnerability found in the WordPress JS Help Desk Plugin versions 3.1.1 and earlier.

This vulnerability allows attackers to delete critical files from a website by exploiting broken access control mechanisms in the plugin.

Because of this, the website could malfunction or break entirely.

Impact Analysis

An attacker exploiting this vulnerability can delete important files on your website, which may cause the site to malfunction or become completely inoperable.

This could lead to downtime, loss of data, and disruption of services provided by the website.

Since the vulnerability is actively exploitable and may be used in mass-exploitation campaigns, the risk of attack is significant.

Mitigation Strategies

To mitigate the CVE-2026-56054 vulnerability in the JS Help Desk Plugin (versions 3.1.1 and earlier), the immediate recommended action is to update the plugin to version 3.1.2 or later.

If updating the plugin is not possible immediately, users should seek assistance from their hosting provider or a web developer.

Additionally, Patchstack has provided a mitigation rule that can be used to block attacks targeting this vulnerability until the plugin is updated.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56054. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart