Missing Authorization
9 records32.1%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 28 vulnerability records associated with JS Help Desk – AI-Powered Support & Ticketing System, published between 2018 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2018 | 1 | |
| 2023 | 8 | |
| 2024 | 3 | |
| 2025 | 7 | |
| 2026 | 9 |
| Severity | Records | Share |
|---|---|---|
| Critical | 6 | 21.4% |
| High | 10 | 35.7% |
| Medium | 12 | 42.9% |
First: 2023. Latest: 2026.
First: 2023. Latest: 2026.
First: 2025. Latest: 2026.
First: 2018. Latest: 2023.
First: 2023. Latest: 2023.
First: 2024. Latest: 2025.
First: 2024. Latest: 2024.
First: 2025. Latest: 2025.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
3.1.13.1.23.1.03.0.53.0.42.8.33.0.22.9.22.9.32.8.92.8.82.8.72.8.42.8.22.7.82.7.22.0.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-3.1.0 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 - Unauthenticated Insecure Direct Object Reference | June 26, 2026 | 3.1.1 | Medium |
*-3.1.1 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion | June 25, 2026 | 3.1.2 | High |
*-3.0.9 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Unauthenticated SQL Injection | June 2, 2026 | 3.1.0 | High |
*-3.0.9 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Missing Authorization | June 2, 2026 | 3.1.0 | Medium |
*-3.0.4 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter | March 25, 2026 | 3.0.5 | High |
*-3.0.3 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference | March 23, 2026 | 3.0.4 | Medium |
*-3.0.3 | JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) SQL Injection | March 20, 2026 | 3.0.4 | Medium |
*-2.8.2 | JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie | March 3, 2026 | 2.8.3 | High |
*-3.0.1 | JS Help Desk <= 3.0.1 - Authenticated (Subscriber+) SQL Injection | February 11, 2026 | 3.0.2 | Medium |
*-2.9.2 | JS Help Desk <= 2.9.2 - Unauthenticated Arbitrary File Deletion | March 27, 2025 | 2.9.3 | Critical |
*-2.9.1 | JS Help Desk <= 2.9.1 - Unauthenticated Arbitrary File Download | March 27, 2025 | 2.9.2 | High |
*-2.9.2 | JS Help Desk <= 2.9.2 - Unauthenticated Local File Inclusion | March 27, 2025 | 2.9.3 | Critical |
*-2.9.2 | JS Help Desk <= 2.9.2 - Missing Authorization | March 27, 2025 | 2.9.3 | Medium |
*-2.9.2 | JS Help Desk <= 2.9.2 - Unauthenticated SQL Injection | March 27, 2025 | 2.9.3 | High |
*-2.8.8 | JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory | February 12, 2025 | 2.8.9 | High |
*-2.8.8 | JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insecure Direct Object Reference | February 3, 2025 | 2.8.9 | Medium |
*-2.8.7 | JS Help Desk – Best Help Desk & Support Plugin <= 2.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting | November 1, 2024 | 2.8.8 | Medium |
*-2.8.6 | JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution | August 12, 2024 | 2.8.7 | Critical |
*-2.8.3 | JS Help Desk – Best Help Desk & Support Plugin <= 2.8.3 - Missing Authorization | April 5, 2024 | 2.8.4 | Medium |
[*, 2.8.2) | JS Help Desk <= 2.8.1 - Unauthenticated SQL Injection via email and trackingid | December 21, 2023 | 2.8.2 | Critical |
*-2.7.7 | JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Administrator+) Arbitrary File Upload | August 17, 2023 | 2.7.8 | High |
*-2.7.7 | JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Subscriber+) Insecure Direct Object Reference | June 20, 2023 | 2.7.8 | Medium |
*-2.7.1 | JS Help Desk <= 2.7.1 - Cross-Site Request Forgery | January 27, 2023 | 2.7.2 | Medium |
*-2.7.1 | JS Help Desk <= 2.7.1 - Unauthenticated SQL Injection | January 27, 2023 | 2.7.2 | High |
2.7.1 | JS Help Desk <= 2.7.1 - Missing Authorization to Plugin Settings Update | January 27, 2023 | 2.7.2 | Critical |
Selected source records
Published: June 26, 2026
Published: June 25, 2026
Published: June 2, 2026
Published: June 2, 2026
Published: March 25, 2026
Published: March 23, 2026
Published: March 20, 2026
Published: March 3, 2026
Published: August 12, 2024
Published: January 27, 2023
Published: March 27, 2025
Published: December 21, 2023
Published: January 27, 2023
Published: March 27, 2025
Published: June 25, 2026
Published: June 25, 2018
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.