CVE-2026-15209
Received Received - Intake

Unauthorized Ticket Data Exposure in JS Help Desk WordPress Plugin

Vulnerability report for CVE-2026-15209, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
js_help_desk js_help_desk to 3.1.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the JS Help Desk WordPress plugin before version 3.1.5. It allows a low-privileged authenticated user to access another user's ticket by supplying its ID without proper verification. This exposes sensitive information like the reporter's personally identifiable information (PII) and message content.

Detection Guidance

To detect this vulnerability, check if your WordPress site uses the JS Help Desk plugin version below 3.1.5. Log in as a subscriber and manually test by accessing different ticket IDs via URL manipulation (e.g., changing the ID parameter). If sensitive data is exposed, the plugin is vulnerable.

Impact Analysis

If you use this plugin, an attacker with basic access could read private support tickets, exposing sensitive data such as user identities, contact details, and confidential messages. This could lead to privacy breaches or misuse of information.

Compliance Impact

This vulnerability could violate GDPR by exposing PII without consent and HIPAA by leaking protected health information if tickets contain such data. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Update the JS Help Desk WordPress plugin to version 3.1.5 or later to address the unauthorized ticket access issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15209. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart