Unauthenticated SQL Injection Vulnerability in JS Help Desk by JS Support
CVE-2026-48886
9.3CRITICAL
What is CVE-2026-48886?
The JS Help Desk plugin versions up to 3.0.9 are susceptible to an unauthenticated SQL injection vulnerability. This security flaw can be exploited by attackers to execute arbitrary SQL queries, potentially resulting in unauthorized access to the database, data leakage, or manipulation of stored information. Organizations using this plugin are advised to take immediate action to patch the vulnerability and mitigate the risk of attacks targeting their systems.
Affected Version(s)
JS Help Desk <= 3.0.9