CVE-2024-8548

Oct. 1, 2024, 8:15 a.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

KB Support - WordPress Help Desk and Knowledge Base plugin

  • up to 1.6.6

Source

security@wordfence.com

Tags

CVE-2024-8548 details

Published : Oct. 1, 2024, 8:15 a.m.
Last Modified : Oct. 1, 2024, 8:15 a.m.

Description

The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants.

CVSS Score

1 2 3 4 5 6 7 8.1 9 10

Weakness

Weakness Name Description
CWE-862 Missing Authorization The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

8.1

Exploitability Score

2.8

Impact Score

5.2

Base Severity

HIGH

References

URL Source
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L138 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L172 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L211 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L240 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L458 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L531 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L580 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L605 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L630 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L649 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L801 security@wordfence.com
https://plugins.trac.wordpress.org/browser/kb-support/trunk/includes/ajax-functions.php#L869 security@wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/5fb90b3b-08bd-4887-a6bf-054b42d3e403?source=cve security@wordfence.com
This website uses the NVD API, but is not approved or certified by it.