The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
CVSS
No CVSS.
References
Configurations
History
10 Feb 2025, 16:00
Type | Values Removed | Values Added |
---|---|---|
First Time |
Logon kb Support
Logon |
|
CWE | ||
CPE | cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : unknown |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - Third Party Advisory | |
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - Product | |
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - Product |
01 Oct 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-01 08:15
Updated : 2025-02-10 16:00
NVD link : CVE-2024-8632
Mitre link : CVE-2024-8632
JSON object : View
Products Affected
logon
- kb_support
CWE
No CWE.