Unauthenticated SQL Injection Vulnerability in JS Help Desk by JS Support
CVE-2026-48886

9.3CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 June 2026

What is CVE-2026-48886?

The JS Help Desk plugin versions up to 3.0.9 are susceptible to an unauthenticated SQL injection vulnerability. This security flaw can be exploited by attackers to execute arbitrary SQL queries, potentially resulting in unauthorized access to the database, data leakage, or manipulation of stored information. Organizations using this plugin are advised to take immediate action to patch the vulnerability and mitigate the risk of attacks targeting their systems.

Affected Version(s)

JS Help Desk <= 3.0.9

References

CVSS V3.1

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sequence_X0 | Patchstack Bug Bounty Program
.