CVE-2024-8632
CVSS V2 None
CVSS V3 None
Description
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
Overview
- CVE ID
- CVE-2024-8632
- Assigner
- Wordfence
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-10-01T07:30:13.274Z
- Last Modified Date
- 2024-10-01T13:44:02.056Z
Weakness Enumerations
References
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-8632 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-8632 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-10-06 21:31:05 | Added to TrackCVE |