CVE-2024-8632
01.10.2024, 08:15
The KB Support WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.Enginsight
Vendor | Product | Version |
---|---|---|
cagdasdag | kb_support_wordpress_help_desk_and_knowledge_base | 𝑥 ≤ 1.6.6 |
logon | kb_support | 𝑥 < 1.6.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration