Project Subscriptions
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-49255 | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 18:30:00 +0000
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants. | The KB Support – WordPress Help Desk and Knowledge Base plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the /includes/ajax-functions.php file all versions up to, and including, 1.6.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform multiple administrative actions, such as replying to arbitrary tickets, updating the status of any post, deleting any post, adding notes to tickets, flagging or unflagging tickets, and adding or removing ticket participants. |
| References |
|
Mon, 10 Feb 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Logon
Logon kb Support |
|
| CPEs | cpe:2.3:a:logon:kb_support:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Logon
Logon kb Support |
Tue, 01 Oct 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cagdasdag
Cagdasdag kb Support Wordpress Help Desk And Knowledge Base |
|
| CPEs | cpe:2.3:a:cagdasdag:kb_support_wordpress_help_desk_and_knowledge_base:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cagdasdag
Cagdasdag kb Support Wordpress Help Desk And Knowledge Base |
|
| Metrics |
ssvc
|
Tue, 01 Oct 2024 07:45:00 +0000
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:56:26.118Z
Reserved: 2024-09-06T19:19:03.349Z
Link: CVE-2024-8548
Updated: 2024-10-01T15:40:23.013Z
Status : Modified
Published: 2024-10-01T08:15:03.400
Modified: 2026-04-08T18:22:40.577
Link: CVE-2024-8548
No data.
OpenCVE Enrichment
No data.
EUVD