plugin

Zendesk Vulnerabilities

2 known security issues reported for the Zendesk WordPress plugin. Most recent disclosed Dec 9, 2024.

1 medium

Running Zendesk on your site? Check whether your installed version is affected.

Scan your site free

Zendesk Support for WordPress [zendesk] < 1.8.5

unknown

[en] Missing Authorization vulnerability in Zendesk Zendesk Support for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zendesk Support for WordPress: from n/a through 1.8.4.

Affected:
up to 1.8.5
Fixed in:
1.8.5
Disclosed:
Dec 9, 2024

CVE-2023-23716 on NVD →

Zendesk Support for WordPress <= 1.8.4 - Cross-Site Request Forgery

medium

The Zendesk Support for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.4. This is due to missing nonce validation on an unknown function. This makes it possible for unauthenticated attackers to invoke the functions via a forged request granted they can t...

CVSS:
4.3
Affected:
up to 1.8.4
Fixed in:
1.8.5
Disclosed:
Apr 18, 2023

CVE-2023-23716 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database