The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
References
Configurations
History
10 Feb 2025, 16:00
Type | Values Removed | Values Added |
---|---|---|
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L342 - Product | |
References | () https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L439 - Product | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/767b1234-5b4a-4baa-9048-7b2e413cdba5?source=cve - Third Party Advisory | |
CPE | cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:* | |
First Time |
Logon kb Support
Logon |
Information
Published : 2024-10-01 08:15
Updated : 2025-02-10 16:00
NVD link : CVE-2024-8632
Mitre link : CVE-2024-8632
CVE.ORG link : CVE-2024-8632
JSON object : View
Products Affected
logon
- kb_support
CWE
CWE-862
Missing Authorization