Extension WordPress

Vulnérabilités KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

Cette page rassemble les failles publiées pour KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

9Vulnérabilités
0Critiques
8Avec correctif
8,1CVSS maximal

Historique de sécurité

CVE et vulnérabilités de KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

9 fiches

CVE-2024-13604 Élevée · 7,5
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin <= 1.7.4 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible…

Versions affectées

*-1.7.4

Correctif

Non indiqué

Publication

04/04/2025

CVE-2024-8548 Élevée · 8,1
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 – Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up…

Versions affectées

*-1.6.6

Correctif

1.6.7

Publication

30/09/2024

CVE-2024-8632 Moyenne · 6,5
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 – Missing Authorization to Unauthenticated Ticket Reply Exposure

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing capability check on the 'kbs_ajax_load_front_end_replies' and 'kbs_ajax_mark_reply_as_read' functions in all versions up…

Versions affectées

*-1.6.6

Correctif

1.6.7

Publication

30/09/2024

CVE-2024-33589 Moyenne · 4,3
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support <= 1.6.0 – Missing Authorization

The KB Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the kbs_ajax_display_ticket_notes and kbs_ajax_display_ticket_replies function in versions up to, and including, 1.6.0. This makes it possible for authenticated…

Versions affectées

*-1.6.0

Correctif

1.6.1

Publication

25/04/2024

Vulnérabilité Moyenne · 4,3
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support <= 1.5.88 – Missing Authorization to Authenticated (Subscriber+) User Data Retrieval

The KB Support plugin for WordPress is vulnerable to user data retrieval in versions up to, and including, 1.5.88. This is due to to a missing capability check on the kbs_ajax_get_customer_data() function. This makes it possible for authenticated…

Versions affectées

[*, 1.5.89)

Correctif

1.5.89

Publication

12/07/2023

CVE-2023-37890 Moyenne · 5,4
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support <= 1.5.88 – Missing Authorization to Sensitive Data Exposure

The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access…

Versions affectées

*-1.5.88

Correctif

1.5.89

Publication

11/07/2023

CVE-2023-25983 Moyenne · 4,4
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support <= 1.5.84 – Authenticated (Subscriber+) CSV Injection

The KB Support plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, KB Support. This allows subscriber-level attackers to embed untrusted input into exported CSV files, which can result in code execution when…

Versions affectées

*-1.5.84

Correctif

1.5.85

Publication

24/02/2023

CVE-2022-27852 Moyenne · 4,7
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin

KB Support – WordPress Help Desk <= 1.5.5 – Multiple Unauthenticated Stored Cross-Site Scripting

The plugin KB Support – WordPress Help Desk versions up to 1.5.5 are vulnerable to Cross-Site Scripting. The vulnerabilities allow unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected…

Versions affectées

*-1.5.5

Correctif

1.5.6

Publication

15/04/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités