CVE-2023-7337Disclosure

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in version 2.8.2 due to an incomplete fix for CVE-2023-50839 where a second sink was left with insufficient escaping on the user supplied values and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-04); latest day: 1
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-12: 1PoC Mentioned / Linked · 2026-03-12: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-12: 103-0403-12
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure3General1
2026-03-121
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2023-7337 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in versio… https://www.cve.org/CVERecord?id=CVE-2023-7337

    Post summary

    The text discloses a SQL injection vulnerability in the WordPress plugin JS Help Desk, stating that the flaw is triggered via the 'js-support-ticket-token-tkstatus' cookie.

    00010502
    56.6K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2023-7337 - critical 🚨 JS Help Desk <= 2.8.2 - SQL Injection > JS Help Desk WordPress plugin 2.8.2 contains a SQL injection caused by insufficient e... 👾 https://cloud.projectdiscovery.io/library/CVE-2023-7337 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces a critical SQL injection flaw in JS Help Desk versions up to 2.8.2 and provides a link to a detection template, but offers no exploit code, patch, or evidence of active attacks.

    00000117
    902 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2023-7337 SQL Injection Vulnerability in WordPress JS Help Desk Plugin 2.8.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2023-7337

    Post summary

    The post announces CVE-2023-7337 as a SQL injection flaw in the WordPress JS Help Desk Plugin 2.8.2, without providing PoC, exploit, or mitigation details.

    0000059
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2023-7337 📊 Severity: 7.5 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2023-7337 #CVE-2023-7337 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/x1oXHsRLuQ

    Post summary

    The tweet simply announces CVE‑2023‑7337 with a 7.5 severity score and indicates it affects WordPress; no technical, exploit, or mitigation details are provided.

    0000073
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2023-7337 The JS Help Desk – AI-Powered Support & Ticketing System plugin for WordPress is vulnerable to SQL Injection via the 'js-support-ticket-token-tkstatus' cookie in versio… https://www.cve.org/CVERecord?id=CVE-2023-7337 ----- Traducción: CVE-2023-7337 El … http://infoflow.cloud`

    Post summary

    A new CVE (CVE‑2023‑7337) affecting the JS Help Desk WordPress plugin is disclosed, revealing SQL injection via a cookie; no PoC, exploit, patch, or active exploitation is mentioned.

    0000053
    55 followersView on X

Explore more