6 results (0.001 seconds)

CVSS: 10.0EPSS: 1%CPEs: 1EXPL: 0

08 Jul 2025 — The Support Board plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the sb_file_delete function in all versions up to, and including, 3.8.0. This makes it possible for attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). An attacker can leverage CVE-2025-4855 vulnerability to exploit this vulnerability unauthenticated. • https://codecanyon.net/item/support-board-help-desk-and-chat/20359943 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

08 Jul 2025 — The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated. • https://codecanyon.net/item/support-board-help-desk-and-chat/20359943 • CWE-639: Authorization Bypass Through User-Controlled Key •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 2

18 Oct 2021 — The Support Board WordPress plugin before 3.3.6 does not have any CSRF checks in actions handled by the include/ajax.php file, which could allow attackers to make logged in users do unwanted actions. For example, make an admin delete arbitrary files El plugin Support Board de WordPress versiones anteriores a 3.3.6, no presenta ninguna comprobación de tipo CSRF en las acciones administradas por el archivo include/ajax.php, lo que podría permitir a atacantes hacer que usuarios registrados realicen acciones no... • https://noob3xploiter.medium.com/support-board-3-3-4-arbitrary-file-deletion-to-remote-code-execution-da4c45b45c83 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 6.4EPSS: 3%CPEs: 1EXPL: 3

07 Oct 2021 — The Support Board WordPress plugin before 3.3.5 allows Authenticated (Agent+) users to perform Cross-Site Scripting attacks by placing a payload in the notes field, when an administrator or any authenticated user go to the chat the XSS will be automatically executed. El plugin Support Board de WordPress versiones anteriores a 3.3.5, permite a usuarios autenticados (Agente+) llevar a cabo ataques de tipo Cross-Site Scripting al colocar un payload en el campo notes, cuando un administrador o cualquier usuario... • https://github.com/dldygnl/CVE-2021-24807 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.8EPSS: 58%CPEs: 1EXPL: 2

03 Sep 2021 — The Support Board WordPress plugin before 3.3.4 does not escape multiple POST parameters (such as status_code, department, user_id, conversation_id, conversation_status_code, and recipient_id) before using them in SQL statements, leading to SQL injections which are exploitable by unauthenticated users. El plugin Support Board de WordPress versiones anteriores a 3.3.4, no escapa de múltiples parámetros POST (como status_code, department, user_id, conversation_id, conversation_status_code, y recipient_id) ant... • https://github.com/dldygnl/CVE-2021-24741 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 1

16 Oct 2018 — In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action. En el plugin Schiocco "Support Board - Chat And Help Desk" 1.2.3 para WordPress, se ha descubierto una vulnerabilidad Cross-Site Scripting (XSS) persistente en las áreas de subida de archivos de las secciones Chat y Help Desk mediante el parámetro ... • https://packetstorm.news/files/id/149806 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •