The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
                
            References
                    Configurations
                    History
                    10 Feb 2025, 16:00
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:* | |
| References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - Product | |
| References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - Product | |
| References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - Third Party Advisory | |
| First Time | Logon kb Support Logon | 
Information
                Published : 2024-10-01 08:15
Updated : 2025-02-10 16:00
NVD link : CVE-2024-8632
Mitre link : CVE-2024-8632
CVE.ORG link : CVE-2024-8632
JSON object : View
Products Affected
                logon
- kb_support
CWE
                
                    
                        
                        CWE-862
                        
            Missing Authorization
