Extension WordPress
Vulnérabilités KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin
Cette page rassemble les failles publiées pour KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin
9 fiches
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible…
*-1.7.4
Non indiqué
04/04/2025
KB Support <= 1.6.7 – Unauthenticated Open Redirect
The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 1.6.7. This is due to insufficient validation on the redirect…
*-1.6.7
1.6.8
24/01/2025
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 – Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up…
*-1.6.6
1.6.7
30/09/2024
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 – Missing Authorization to Unauthenticated Ticket Reply Exposure
The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up…
*-1.6.6
1.6.7
30/09/2024
KB Support <= 1.6.0 – Missing Authorization
The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the kbs_ajax_display_ticket_notes and kbs_ajax_display_ticket_replies function in versions up to, and including, 1.6.0. This makes it possible for authenticated…
*-1.6.0
1.6.1
25/04/2024
KB Support <= 1.5.88 – Missing Authorization to Authenticated (Subscriber+) User Data Retrieval
The KB Support plugin for WordPress is vulnerable to user data retrieval in versions up to, and including, 1.5.88. This is due to to a missing capability check on the kbs_ajax_get_customer_data() function. This makes it possible for authenticated…
[*, 1.5.89)
1.5.89
12/07/2023
KB Support <= 1.5.88 – Missing Authorization to Sensitive Data Exposure
The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access…
*-1.5.88
1.5.89
11/07/2023
KB Support <= 1.5.84 – Authenticated (Subscriber+) CSV Injection
The KB Support plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, KB Support. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when…
*-1.5.84
1.5.85
24/02/2023
KB Support – WordPress Help Desk <= 1.5.5 – Multiple Unauthenticated Stored Cross-Site Scripting
The plugin KB Support – WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabilities allow unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…
*-1.5.5
1.5.6
15/04/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.