S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Mar 12, 2026

CVE-2023-7337 Scanner

CVE-2023-7337 Scanner - SQL Injection (SQLi) vulnerability in JS Help Desk

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-7337
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
JS Help Desk – AI-Powered Support & Ticketing Systemby rabilal
0
Updated Aug 22, 2026View on NVD →
Detail

JS Help Desk is a WordPress plugin that provides support ticket functionality for websites, allowing developers to manage customer support within their WordPress environment. It is widely used by companies seeking to store and track customer issues, offering features like ticket creation, status tracking, and email notifications. Businesses implement this plugin to streamline customer service processes, ensuring effective communication and issue resolution. Primarily, it is utilized in environments where interaction with customers is crucial for operational success. The software is favored for its simplicity and integration capabilities within the WordPress ecosystem. Due to its widespread use, vulnerabilities in this plugin can affect a large number of WordPress installations.

SQL Injection (SQLi) vulnerabilities occur when user inputs are improperly escaped or sanitized, allowing attackers to alter database queries. This vulnerability in JS Help Desk allows attackers to extract sensitive information from the database through the 'js-support-ticket-token-tkstatus' cookie parameter. The fault lies in the unsanitized values used directly in SQL commands. Successful exploitation does not require authentication, adding a critical dimension to the vulnerability's severity. If exploited, it allows attackers to access data such as user credentials and other sensitive database information. The resultant data breach can severely compromise user privacy and platform integrity.

The specific technical issue with this vulnerability is insufficient escaping and preparation of user-supplied values in a cookie parameter. The 'js-support-ticket-token-tkstatus' cookie is manipulated, altering the way the backend server interprets database queries. This results in unauthorized data access, as the injected SQL statements reconfigure how the database processes commands. Attackers exploit this by extracting data or modifying the database structure undetected. The vulnerability exists due to lazy coding practices, where input variables are integrally used in database cursors without validation. The primary endpoint vulnerable to this exploit is the ticket management interface on the WordPress backend.

Exploiting this vulnerability allows attackers to access sensitive database information, leading to data breaches and potential leaks of user data. Users' personal and financial information could be exposed if stored within the breached database. The security of entire WordPress installations using this plugin might be compromised, leading to broader site attacks. Moreover, the unauthorized extraction of database contents can result in regulatory repercussions for website operators and loss of user trust. In worst-case scenarios, the compromised data could facilitate further attacks like phishing or identity theft.

REFERENCES

Solution Advice
  • Update JS Help Desk plugin to the latest version to mitigate the vulnerability.
  • Implement input validation for all user-supplied data to prevent SQL Injection.
  • Regularly audit code for injection vulnerabilities and sanitize inputs appropriately.
  • Apply database privilege limitations to reduce the risk of a successful SQL injection leading to excessive data exposure.
  • Introduce comprehensive logging and monitoring to detect suspicious database queries early.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.