CVE-2024-8632

CVSS V2 None CVSS V3 None
Description
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to read replies of any ticket, and mark any reply as read.
Overview
  • CVE ID
  • CVE-2024-8632
  • Assigner
  • Wordfence
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-10-01T07:30:13.274Z
  • Last Modified Date
  • 2024-10-01T13:44:02.056Z
History
Created Old Value New Value Data Type Notes
2024-10-06 21:31:05 Added to TrackCVE