Summary
CVE-2026-14930 is a Missing Authorization (CWE-862) vulnerability in the JS Help Desk WordPress plugin (all versions before 3.1.4), rated High severity with a CVSS v3.1 score of 7.5. The plugin’s front-end request dispatcher performs no authorization check, nonce validation, or ticket ownership verification, enabling fully unauthenticated remote attackers to upload files and attach them to any user’s support ticket on an affected site. With over 7,000 active installations, the potential scope of exposure is meaningful for organizations relying on the plugin for customer support operations.
Technical details
- Root cause: The plugin’s front-end request dispatcher does not enforce any authentication, nonce, or ownership check before processing file attachment operations. An unauthenticated attacker can directly invoke the attachment handler by crafting a POST request using the parameters
jstmod=attachmentandtask=saveattachmentsalong with an arbitrary targetticketid. - Trigger conditions: No credentials or session tokens are required. Ticket IDs can be known or enumerated, as the dispatcher accepts arbitrary ticket IDs without ownership validation.
- Attack vector: Network-accessible, unauthenticated HTTP POST request to the plugin’s publicly exposed front-end dispatcher endpoint — no special network position or prior access is required.
- Impact: An attacker can attach files to any user’s support ticket without authorization. The plugin’s default file-extension allowlist restricts uploads to inert file types, preventing direct remote code execution via webshell. However, the unprotected dispatcher grants unauthenticated access to the broader attachment and ticket handling mechanism, exposing support ticket data (which routinely contains PII, credentials, and sensitive business communications) with a Confidentiality impact rated HIGH by CVSS.
Affected software
- JS Help Desk WordPress plugin (slug:
js-support-ticket, vendor: JoomSky) — all versions before 3.1.4
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the JS Help Desk plugin to version 3.1.4 or later (current release: 3.1.6). Version 3.1.4 introduces strict authorization and nonce verification on the front-end request dispatcher, directly remediating this flaw.
- If immediate patching is not feasible: Temporarily disable the plugin, or apply WAF rules or server-level controls to block unauthenticated POST requests to the plugin’s front-end attachment endpoint until the update can be applied.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

