KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
high
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in...
- CVSS:
- 7.5
- Affected:
- up to 1.7.4
- Fix:
- No patched version reported
- Disclosed:
- Apr 4, 2025
CVE-2024-13604 on NVD →
KB Support <= 1.6.7 - Unauthenticated Open Redirect
medium
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.6.7. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users t...
- CVSS:
- 6.1
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.8
- Disclosed:
- Jan 24, 2025
CVE-2025-24741 on NVD →
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
high
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up to, and including, 1.6.6. This makes it possible for authenticated atta...
- CVSS:
- 8.1
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Sep 30, 2024
CVE-2024-8548 on NVD →
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure
medium
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it pos...
- CVSS:
- 6.5
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Sep 30, 2024
CVE-2024-8632 on NVD →
KB Support <= 1.6.0 - Missing Authorization
medium
The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the kbs_ajax_display_ticket_notes and kbs_ajax_display_ticket_replies function in versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with subscriber-level access a...
- CVSS:
- 4.3
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.1
- Disclosed:
- Apr 25, 2024
CVE-2024-33589 on NVD →
KB Support <= 1.5.88 - Missing Authorization to Authenticated (Subscriber+) User Data Retrieval
medium
The KB Support plugin for WordPress is vulnerable to user data retrieval in versions up to, and including, 1.5.88. This is due to to a missing capability check on the kbs_ajax_get_customer_data() function. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute the...
- CVSS:
- 4.3
- Affected:
- up to 1.5.89
- Fixed in:
- 1.5.89
- Disclosed:
- Jul 12, 2023
KB Support <= 1.5.88 - Missing Authorization to Sensitive Data Exposure
medium
The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access or higher to extract sensitive data including customer...
- CVSS:
- 5.4
- Affected:
- up to 1.5.88
- Fixed in:
- 1.5.89
- Disclosed:
- Jul 11, 2023
CVE-2023-37890 on NVD →
KB Support <= 1.5.84 - Authenticated (Subscriber+) CSV Injection
medium
The KB Support plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, KB Support. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable conf...
- CVSS:
- 4.4
- Affected:
- up to 1.5.84
- Fixed in:
- 1.5.85
- Disclosed:
- Feb 24, 2023
CVE-2023-25983 on NVD →
KB Support – WordPress Help Desk <= 1.5.5 - Multiple Unauthenticated Stored Cross-Site Scripting
medium
The plugin KB Support – WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabilities allow unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- CVSS:
- 4.7
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.6
- Disclosed:
- Apr 15, 2022
CVE-2022-27852 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database