Unauthenticated Insecure Direct Object References in JS Help Desk by WordPress
CVE-2026-57652
5.3MEDIUM
What is CVE-2026-57652?
An unauthenticated Insecure Direct Object Reference (IDOR) vulnerability exists in versions of JS Help Desk up to 3.1.0. This issue allows attackers to access unauthorized data or perform actions as if they were legitimate users by manipulating object references within requests. This flaw can significantly compromise the security of systems using this plugin, leading to potential data leaks and unauthorized access.
Affected Version(s)
JS Help Desk <= 3.1.0