سایبرنامه
medium

CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated user can supply another user's ticket ID and read that ticket's contents, including the reporter's PII and message body.

امتیاز CVSS

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

تحلیلِ بردارِ CVSS

CWE
CWE-639
تاریخ انتشار
۹ مرداد ۱۴۰۵

منابع