Page 2 of 6 results (0.005 seconds)

CVSS: 9.1EPSS: %CPEs: 1EXPL: 0

The JS Help Desk plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on an unknown function in versions up to, and including, 2.7.1. This makes it possible for unauthenticated attackers to update the plugin's settings. • CWE-862: Missing Authorization •