The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.
References
Link | Resource |
---|---|
https://codecanyon.net/item/support-board-help-desk-and-chat/20359943 | Product |
https://www.wordfence.com/threat-intel/vulnerabilities/id/afd48bc8-d490-4a3e-97fc-70cf008cbf66?source=cve | Third Party Advisory |
Configurations
History
14 Jul 2025, 15:10
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-09 00:15
Updated : 2025-07-14 15:10
NVD link : CVE-2025-4855
Mitre link : CVE-2025-4855
CVE.ORG link : CVE-2025-4855
JSON object : View
Products Affected
schiocco
- support_board
CWE
CWE-639
Authorization Bypass Through User-Controlled Key