plugin

Kb Support Vulnerabilities

9 known security issues reported for the Kb Support WordPress plugin. Most recent disclosed Apr 4, 2025.

2 high 7 medium

Running Kb Support on your site? Check whether your installed version is affected.

Scan your site free

KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

high

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in...

CVSS:
7.5
Affected:
up to 1.7.4
Fix:
No patched version reported
Disclosed:
Apr 4, 2025

CVE-2024-13604 on NVD →

KB Support <= 1.6.7 - Unauthenticated Open Redirect

medium

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.6.7. This is due to insufficient validation on the redirect url supplied. This makes it possible for unauthenticated attackers to redirect users t...

CVSS:
6.1
Affected:
up to 1.6.7
Fixed in:
1.6.8
Disclosed:
Jan 24, 2025

CVE-2025-24741 on NVD →

KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions

high

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up to, and including, 1.6.6. This makes it possible for authenticated atta...

CVSS:
8.1
Affected:
up to 1.6.6
Fixed in:
1.6.7
Disclosed:
Sep 30, 2024

CVE-2024-8548 on NVD →

KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure

medium

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it pos...

CVSS:
6.5
Affected:
up to 1.6.6
Fixed in:
1.6.7
Disclosed:
Sep 30, 2024

CVE-2024-8632 on NVD →

KB Support <= 1.6.0 - Missing Authorization

medium

The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the kbs_ajax_display_ticket_notes and kbs_ajax_display_ticket_replies function in versions up to, and including, 1.6.0. This makes it possible for authenticated attackers, with subscriber-level access a...

CVSS:
4.3
Affected:
up to 1.6.0
Fixed in:
1.6.1
Disclosed:
Apr 25, 2024

CVE-2024-33589 on NVD →

KB Support <= 1.5.88 - Missing Authorization to Authenticated (Subscriber+) User Data Retrieval

medium

The KB Support plugin for WordPress is vulnerable to user data retrieval in versions up to, and including, 1.5.88. This is due to to a missing capability check on the kbs_ajax_get_customer_data() function. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to execute the...

CVSS:
4.3
Affected:
up to 1.5.89
Fixed in:
1.5.89
Disclosed:
Jul 12, 2023

KB Support <= 1.5.88 - Missing Authorization to Sensitive Data Exposure

medium

The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access or higher to extract sensitive data including customer...

CVSS:
5.4
Affected:
up to 1.5.88
Fixed in:
1.5.89
Disclosed:
Jul 11, 2023

CVE-2023-37890 on NVD →

KB Support <= 1.5.84 - Authenticated (Subscriber+) CSV Injection

medium

The KB Support plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, KB Support. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable conf...

CVSS:
4.4
Affected:
up to 1.5.84
Fixed in:
1.5.85
Disclosed:
Feb 24, 2023

CVE-2023-25983 on NVD →

KB Support – WordPress Help Desk <= 1.5.5 - Multiple Unauthenticated Stored Cross-Site Scripting

medium

The plugin KB Support – WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabilities allow unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

CVSS:
4.7
Affected:
up to 1.5.5
Fixed in:
1.5.6
Disclosed:
Apr 15, 2022

CVE-2022-27852 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database