PT-2024-11741 · WordPress · Js Help Desk – Best Help Desk & Support Plugin

Re-Alter

+1

·

Published

2024-12-13

·

Updated

2024-12-15

·

CVE-2022-46838

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions JS Help Desk – Best Help Desk & Support Plugin versions prior to 2.7.1
Description The issue affects the JS Help Desk – Best Help Desk & Support Plugin, allowing exploitation of incorrectly configured access control security levels due to a missing authorization vulnerability. This vulnerability enables unauthenticated settings changes.
Recommendations For versions prior to 2.7.1, update to version 2.7.1 or later to secure your site. As a temporary workaround, consider restricting access to settings changes until the update is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-46838

Affected Products

Js Help Desk – Best Help Desk & Support Plugin