Extension WordPress

Vulnérabilités JS Help Desk – AI-Powered Support & Ticketing System

Cette page rassemble les failles publiées pour JS Help Desk – AI-Powered Support & Ticketing System, leurs plages de versions affectées et les correctifs signalés dans la base locale.

28Vulnérabilités
6Critiques
28Avec correctif
9,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de JS Help Desk – AI-Powered Support & Ticketing System

28 fiches

CVE-2026-57652 Moyenne · 5,3
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 – Unauthenticated Insecure Direct Object Reference

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.0 due to missing validation on a user controlled key. This…

Versions affectées

*-3.1.0

Correctif

3.1.1

Publication

26/06/2026

CVE-2026-56054 Élevée · 8,8
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 – Authenticated (Subscriber+) Arbitrary File Deletion

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 3.1.1. This makes it possible for…

Versions affectées

*-3.1.1

Correctif

3.1.2

Publication

25/06/2026

CVE-2026-48886 Élevée · 7,5
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 – Unauthenticated SQL Injection

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.9 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-3.0.9

Correctif

3.1.0

Publication

02/06/2026

CVE-2026-48887 Moyenne · 5,3
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 – Missing Authorization

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.0.9. This makes it possible…

Versions affectées

*-3.0.9

Correctif

3.1.0

Publication

02/06/2026

CVE-2026-2511 Élevée · 7,5
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 – Unauthenticated SQL Injection via 'multiformid' Parameter

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the `multiformid` parameter in the `storeTickets()` function in all versions up to, and including, 3.0.4. This is due to…

Versions affectées

*-3.0.4

Correctif

3.0.5

Publication

25/03/2026

CVE-2026-32535 Moyenne · 4,3
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 – Authenticated (Subscriber+) Insecure Direct Object Reference

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.0.3 due to missing validation on a user controlled key. This…

Versions affectées

*-3.0.3

Correctif

3.0.4

Publication

23/03/2026

CVE-2026-32534 Moyenne · 6,5
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 – Authenticated (Subscriber+) SQL Injection

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.3 due to insufficient escaping on the user supplied parameter and lack of sufficient…

Versions affectées

*-3.0.3

Correctif

3.0.4

Publication

20/03/2026

CVE-2023-7337 Élevée · 7,5
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 – Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left…

Versions affectées

*-2.8.2

Correctif

2.8.3

Publication

03/03/2026

CVE-2024-13606 Élevée · 7,5
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'jssupportticketdata' directory. This makes it possible for…

Versions affectées

*-2.8.8

Correctif

2.8.9

Publication

12/02/2025

CVE-2024-13607 Moyenne · 4,3
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 – Authenticated (Subscriber+) Insecure Direct Object Reference

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.8.8 via the 'exportusereraserequest' due to missing validation on…

Versions affectées

*-2.8.8

Correctif

2.8.9

Publication

03/02/2025

CVE-2024-51670 Moyenne · 4,4
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – Best Help Desk & Support Plugin <= 2.8.7 – Authenticated (Administrator+) Stored Cross-Site Scripting

The JS Help Desk – Best Help Desk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.8.7 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-2.8.7

Correctif

2.8.8

Publication

01/11/2024

CVE-2024-7094 Critique · 9,8
JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 – Unauthenticated PHP Code Injection to Remote Code Execution

The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function.…

Versions affectées

*-2.8.6

Correctif

2.8.7

Publication

12/08/2024

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités