JS Help Desk WordPress plugin 2.8.2 contains a SQL injection caused by insufficient escaping and preparation of user-supplied values in 'js-support-ticket-token-tkstatus' cookie, letting unauthenticated attackers extract sensitive database information, exploit requires no authentication.
id: CVE-2023-7337
info:
name: JS Help Desk <= 2.8.2 - SQL Injection
author: Shivam Kamboj
sev
...