[CRITICAL]
·
Self-hosted / private program
·
Disclosed
Summary
An unauthenticated SQL injection in the JS Help Desk WordPress plugin, versions up to and including 3.0.9. No account is needed: a remote visitor can interact with the site's database directly, including reading data out of it.
Impact
Full database read, and everything that follows from that on a WordPress site: user records, password hashes, and whatever the plugin itself stores. Patchstack rated this 9.3 and flagged it as likely to be picked up by mass-exploitation campaigns.
Fix
Patched in 3.1.0. Anything below that is exposed.
References
- CVE-2026-48886
- Patchstack advisory: patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-3-0-9-sql-injection-vulnerability