JS Help Desk – AI-Powered Support & Ticketing System

JS Help Desk – AI-Powered Support & Ticketing System has 33 disclosed vulnerabilities in the WordSec catalog, reported between 2018 and 2026; all 33 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 9.8 out of 10. Severity breakdown: 6 critical and 10 high. 2026 was the busiest year with 14 disclosures.

The most common weakness is SQL Injection, behind 8 of the records (24%). Other recurring categories include Missing Authorization, Authorization Bypass Through User-Controlled Key.

Every one of the 33 issues recorded for JS Help Desk – AI-Powered Support & Ticketing System has a vendor fix available, so running the current release closes all known holes.

19 independent researchers contributed these findings, most of them (5) reported by R3N0. JS Help Desk – AI-Powered Support & Ticketing System is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891010.10.2014Today25.06.20188.8JS Help Desk – Best Help Desk & Support Plugin <= 2.0.5 - Cross-Site Request Forgery CVSS 8.8 · 25.06.201827.01.20238.6JS Help Desk <= 2.7.1 - Unauthenticated SQL Injection CVSS 8.6 · 27.01.20239.1JS Help Desk <= 2.7.1 - Missing Authorization to Plugin Settings Update CVSS 9.1 · 27.01.20235.4JS Help Desk <= 2.7.1 - Cross-Site Request Forgery CVSS 5.4 · 27.01.20236.3JS Help Desk <= 2.7.1 - Missing Authorization CVSS 6.3 · 27.01.20239.8JS Help Desk <= 2.7.1 - Unauthenticated Arbitrary File Upload CVSS 9.8 · 27.01.202320.06.20236.3JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Subscriber+) Insecure Direct Object Reference CVSS 6.3 · 20.06.202317.08.20237.2JS Help Desk – Best Help Desk & Support Plugin <= 2.7.7 - Authenticated (Administrator+) Arbitrary File Upload CVSS 7.2 · 17.08.202321.12.20239.8JS Help Desk <= 2.8.1 - Unauthenticated SQL Injection via email and trackingid CVSS 9.8 · 21.12.202305.04.20245.3JS Help Desk – Best Help Desk & Support Plugin <= 2.8.3 - Missing Authorization CVSS 5.3 · 05.04.202412.08.20249.8JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.6 - Unauthenticated PHP Code Injection to Remote Code Execution CVSS 9.8 · 12.08.202401.11.20244.4JS Help Desk – Best Help Desk & Support Plugin <= 2.8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting CVSS 4.4 · 01.11.202403.02.20254.3JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Authenticated (Subscriber+) Insecure Direct Object Reference CVSS 4.3 · 03.02.202512.02.20257.5JS Help Desk – The Ultimate Help Desk & Support Plugin <= 2.8.8 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory CVSS 7.5 · 12.02.202527.03.20257.5JS Help Desk <= 2.9.1 - Unauthenticated Arbitrary File Download CVSS 7.5 · 27.03.20259.1JS Help Desk <= 2.9.2 - Unauthenticated Arbitrary File Deletion CVSS 9.1 · 27.03.20257.5JS Help Desk <= 2.9.2 - Unauthenticated SQL Injection CVSS 7.5 · 27.03.20259.8JS Help Desk <= 2.9.2 - Unauthenticated Local File Inclusion CVSS 9.8 · 27.03.20255.3JS Help Desk <= 2.9.2 - Missing Authorization CVSS 5.3 · 27.03.202511.02.20266.5JS Help Desk <= 3.0.1 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 11.02.202603.03.20267.5JS Help Desk – AI-Powered Support & Ticketing System 2.8.2 - Unauthenticated SQL Injection via 'js-support-ticket-token-tkstatus' Cookie CVSS 7.5 · 03.03.202620.03.20266.5JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 20.03.202623.03.20264.3JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.3 - Authenticated (Subscriber+) Insecure Direct Object Reference CVSS 4.3 · 23.03.202625.03.20267.5JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.4 - Unauthenticated SQL Injection via 'multiformid' Parameter CVSS 7.5 · 25.03.202602.06.20265.3JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Missing Authorization CVSS 5.3 · 02.06.20267.5JS Help Desk – AI-Powered Support & Ticketing System <= 3.0.9 - Unauthenticated SQL Injection CVSS 7.5 · 02.06.202625.06.20268.8JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion CVSS 8.8 · 25.06.202626.06.20265.3JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.0 - Unauthenticated Insecure Direct Object Reference CVSS 5.3 · 26.06.202613.07.20265.3JS Help Desk – AI-Powered Support & Ticketing System < 3.1.4 - Unauthenticated Arbitrary Media Upload CVSS 5.3 · 13.07.20264.3JS Help Desk – AI-Powered Support & Ticketing System <= 3.1.4 - Insecure Direct Object Reference to Authenticated (Subscriber+) Cross-User Support Ticket Disclosure CVSS 4.3 · 13.07.20264.3JS Help Desk <= 3.1.3 - Authenticated (Contributor+) User Email Disclosure CVSS 4.3 · 13.07.20264.3JS Help Desk <= 3.1.3 - Missing Authorization to Authenticated (Subscriber+) Ticket Reply Modification CVSS 4.3 · 13.07.202604.08.20264.3JS Help Desk – AI-Powered Support & Ticketing System < 3.1.4 - Authenticated (Subscriber+) Information Exposure CVSS 4.3 · 04.08.2026

Strategic Overview

Avg CVSSMedium
6.8/ 10
Patch Coverage100%
Open

0

Fixed

33

Get automatic notifications for all JS Help Desk – AI-Powered Support & Ticketing System vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2025-30901

JS Help Desk <= 2.9.2 - Unauthenticated Local File Inclusion

Read the full analysis

Vulnerability Records

33 records
2026-08-04 00:00CVE-2026-14928
4.3
Medium
Muni Nitish Kumar YaddalaYes
2026-07-13 00:00CVE-2026-14930
5.3
Medium
Shivamani VastralaYes
2026-07-13 00:00CVE-2026-15209
4.3
Medium
Sai Praneeth KotiYes
2026-07-13 00:00CVE-2026-14931
4.3
Medium
Vaibhav NarkhedeYes
2026-07-13 00:00CVE-2026-14929
4.3
Medium
Yaswanth Reddy SunkaraYes
2026-06-26 00:00CVE-2026-57652
5.3
Medium
William MatosYes
2026-06-25 00:00CVE-2026-56054
8.8
High
darooYes
2026-06-02 00:00CVE-2026-48887
5.3
Medium
NvzYes
2026-06-02 00:00CVE-2026-48886
7.5
High
sequence_X0Yes
2026-03-25 00:00CVE-2026-2511
7.5
High
Nabil IrawanYes
Showing 1–10 of 33 reports
JS Help Desk – AI-Powered Support & Ticketing System banner
Latestv4.0.0

JS Help Desk – AI-Powered Support & Ticketing System

JoomSky

Author

JoomSky

3.7(74)
74/100
Last Updated
2026-09-07 (6d ago)
Active Installs
7,000+
Downloads
692,989
Requires WP
5.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2014-10-10 (12y ago)

JS Help Desk is a professional, AI-enhanced helpdesk and customer support system for WordPress. It offers a complete ticketing solution with front-end submission, guest tickets, and a native AI Copilot to boost agent efficiency. Powered by Zywrap, the AI Copilot brings top-tier large language models directly into your ticket editor. Call AI by Code. Zero Prompt Engineering. Key Resources JS Help Desk Demo Plugin Homepage Video Tutorials Free Version Major Features Core Ticketing & Management – Professional Support System: Enterprise-level ticketing for all users. – Unlimited Tickets & Agents: No artificial limits on your growth. – Unlimited Departments: Organize by Sales, Support, Billing, etc. – Priority Management: Highlight urgent issues with custom colors. – Internal Notes: Private notes with a title and a file attachment, never visible to the customer, plus a reason note when a ticket is transferred or assigned. – Custom Statuses: Track ticket progress with clear status messages. Zywrap AI Copilot (New!) – Zero Prompt Engineering: Agents don’t need to write prompts. Simply select a Support Intent (e.g., “Ask for Info” or “Escalate”) and the AI does the rest. – 1-Click Summaries: Instantly summarize long, complex ticket threads to get up to speed in seconds. – Smart Data Extraction: Automatically extract error codes, browser versions, and URLs from customer messages into clean, readable Data Cards. – Instant Translation: Break language barriers by translating customer messages or agent replies with a single click. – Auto-Draft Replies: Generate complete, professional responses based on the context of the entire ticket history. – Dynamic Routing: Automatically routes requests through the best available AI models (OpenAI, Anthropic, Gemini, Groq) via the Zywrap API. User & Agent Experience – Front-end Submission: Users create and track tickets without accessing the dashboard. – Guest/Visitor Tickets: Allow users to open tickets without creating an account. – Fully Responsive: Optimized for smartphones, tablets, and desktops. – HTML Editor: Rich text support for ticket summaries and replies. – Multiple Attachments: Admin-controlled size and file type limits. – Two Agent Tiers, Free: Staff the help desk from ordinary WordPress roles, with no add-on. Help Desk Agent works the queue in full; Help Desk Light Agent reads tickets and writes internal notes but can never answer the customer — the seat for the developer who has to look at the bug but must not reply to the person who reported it. Automation & AI – Instant Answers (New!): As a customer describes their problem, matching knowledge base articles, FAQs and canned responses surface right on the ticket form – so the simple questions get answered before a ticket is ever filed. – AI-Powered Reply Suggestions: Generate context-aware smart responses to save time. – Email Notifications: Automated alerts for new tickets, replies, and status changes. – Field & Email Managers: Full control over 12+ custom fields and HTML email templates. Security & Compliance – GDPR Ready: Built-in tools for data erasure and anonymization. – Spam Protection: Invisible verification with no third-party account needed, or Cloudflare Turnstile, hCaptcha or Google reCAPTCHA v2/v3 if you prefer. Plus per-visitor submission rate limits. – Ticket Activity Timeline: Every ticket keeps a readable event stream — who did what, from where, and which field changed from what to what. – Terms & Conditions: Require agreement before ticket submission. Customization & Reporting – Color Themes: 7 preset palettes to match your brand. – Detailed Reports: Summaries by agent, department, priority, and status. – RTL Ready: Full support for right-to-left languages. – Translations: Supports 35+ languages including French, German, Spanish, Arabic, and Chinese. Shortcodes [jssupportticket] – Control Panel [jssupportticket_addticket] – Add New Ticket form [jssupportticket_mytickets] – User Ticket List Premium Add-Ons JS Help Desk is a complete help desk system with 35+ professional addons. Email Piping – Create/reply to tickets via email. Time Tracking – Log time spent on resolutions. Paid Support – Charge per ticket or subscription. Agents – Multi-agent management & permissions. Agent Auto Assign – Rule-based ticket routing. Multi Forms – Unique forms per department. Merge Tickets – Combine duplicate queries easily. Ticket Overdue – Track SLA deadlines & response times. SMTP – Custom email protocol for reliability. Ban Email – Block specific users or domains. WooCommerce – Connect support to customer orders. Private Credentials – Store & auto-delete sensitive data. Export – Export ticket data/history. Desktop Notification – Real-time browser alerts. Ticket Auto Close – Auto-close inactive ticket threads. Feedback – Collect agent performance ratings. Knowledge Base – Self-service documentation portal. Mail Chimp – Sync users to marketing mailing lists. Announcements – Broadcast news to all support users. Downloads – Share supporting files with customers. FAQ – Database of frequently asked questions. Internal Mail – Agent-to-agent messaging system. Envato Validation – Verify purchase codes for tickets. Front-End Widgets – Display ticket stats in sidebars. Multi Language Emails – Language-based templates. Easy Digital Download – Integrated support for EDD. Privacy & Third-Party Service Disclosure AI Copilot (Zywrap) To provide advanced AI functionalities, JS Help Desk integrates with the Zywrap Cloud API (a third-party service). Data Transmission: When an agent actively uses an AI feature (such as “Generate Reply”, “Summarize”, “Extract Details”, or “Translate”), the content of the specific ticket thread and the customer’s message are securely transmitted to the Zywrap API to generate the response. Opt-In Required: The AI Copilot is completely disabled by default. No data is transmitted unless an Administrator explicitly registers for a Zywrap account, inputs their API Key in the settings, and an agent clicks an AI action button. Data Usage: Data sent to the Zywrap API is used strictly for generating the requested AI text in real-time. Please review the Zywrap Privacy Policy for full details on data handling. Spam Protection (CAPTCHA) JS Help Desk can verify that a ticket submission was made by a person. It ships with a self-hosted verification method, and optionally supports four third-party CAPTCHA services. The default makes no external requests. Out of the box the plugin uses its built-in check – a honeypot field, submission timing, and a small proof of work performed in the visitor’s browser. Nothing is loaded from a third party and no data leaves your site. Third-party services are opt-in. Cloudflare Turnstile, hCaptcha, Google reCAPTCHA v3 and Google reCAPTCHA v2 are offered as alternatives. One is used only after an administrator selects it and enters the site key and secret key of their own account with that provider. If either key is missing, the plugin falls back to the built-in check rather than blocking submissions. Why the provider’s own domain is used. A CAPTCHA is an anti-abuse service that issues a token at its own edge and validates that token against its own records. The challenge script therefore cannot be served from your site, and the response cannot be verified locally – both requests are required for the feature to function. When a provider is selected, its script is loaded on the ticket form and the visitor’s response is verified server-to-server: Cloudflare Turnstile – challenges.cloudflare.com (Terms, Privacy Policy) hCaptcha – js.hcaptcha.com, api.hcaptcha.com (Terms, Privacy Policy) Google reCAPTCHA v2 and v3 – www.google.com/recaptcha (Terms, Privacy Policy) What is transmitted. Only the challenge token generated in the visitor’s browser, your secret key, and the visitor’s IP address are sent to the selected provider’s verification endpoint. Ticket content, subjects, names and e-mail addresses are never sent to a CAPTCHA provider. Choosing none of them. Administrators who do not want any third-party request can leave the built-in provider selected, or turn verification off entirely.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C