PentestingHere
Log in Join
[CRITICAL] · Self-hosted / private program · Disclosed

Unauthenticated SQL injection in JS Help Desk (WordPress) up to 3.0.9

Youssef Eid Youssef Eid CVE-2026-48886 Patchstack 2 Jun 2026

Summary

An unauthenticated SQL injection in the JS Help Desk WordPress plugin, versions up to and including 3.0.9. No account is needed: a remote visitor can interact with the site's database directly, including reading data out of it.

Impact

Full database read, and everything that follows from that on a WordPress site: user records, password hashes, and whatever the plugin itself stores. Patchstack rated this 9.3 and flagged it as likely to be picked up by mass-exploitation campaigns.

Fix

Patched in 3.1.0. Anything below that is exposed.

References

  • CVE-2026-48886
  • Patchstack advisory: patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-3-0-9-sql-injection-vulnerability