PT-2024-11741 · WordPress · Js Help Desk – Best Help Desk & Support Plugin

·

CVE-2022-46838

·

Published

2024-12-13

·

Updated

2024-12-15

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions JS Help Desk – Best Help Desk & Support Plugin versions prior to 2.7.1
Description The issue affects the JS Help Desk – Best Help Desk & Support Plugin, allowing exploitation of incorrectly configured access control security levels due to a missing authorization vulnerability. This vulnerability enables unauthenticated settings changes.
Recommendations For versions prior to 2.7.1, update to version 2.7.1 or later to secure your site. As a temporary workaround, consider restricting access to settings changes until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-46838

Affected Products

Js Help Desk – Best Help Desk & Support Plugin