[CRITICAL]
·
Self-hosted / private program
·
Disclosed
Unauthenticated SQL injection in JS Help Desk (WordPress) up to 3.0.9
Summary
An unauthenticated SQL injection in the JS Help Desk WordPress plugin, versions up to and including 3.0.9. No account is needed: a remote visitor can interact with the site's database directly, including reading data out of it.
Impact
Full database read, and everything that follows from that on a WordPress site: user records, password hashes, and whatever the plugin itself stores. Patchstack rated this 9.3 and flagged it as likely to be picked up by mass-exploitation campaigns.
Fix
Patched in 3.1.0. Anything below that is exposed.
References
- CVE-2026-48886
- Patchstack advisory: patchstack.com/database/wordpress/plugin/js-support-ticket/vulnerability/wordpress-js-help-desk-plugin-3-0-9-sql-injection-vulnerability