CVE-2023-37890
WordPress KB Support Plugin <= 1.5.88 is vulnerable to Broken Access Control
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.
Vulnerabilidad de autorización faltante en WPOmnia KB Support – WordPress Help Desk and Knowledge Base permite Accessing Functionality Not Properly Constrained by ACLs. Los usuarios con un rol tan bajo como suscriptor pueden ver a otros clientes. Este problema afecta a KB Support – WordPress Help Desk and Knowledge Base: desde n/a hasta 1.5.88.
The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access or higher to extract sensitive data including customer data including name, email, phone number.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-07-10 CVE Reserved
- 2023-07-11 CVE Published
- 2024-08-02 CVE Updated
- 2024-10-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-862: Missing Authorization
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/kb-support/wordpress-kb-support-wordpress-help-desk-plugin-1-5-88-sensitive-data-exposure-vulnerability?_s_id=cve | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Liquidweb Search vendor "Liquidweb" | Kb Support Search vendor "Liquidweb" for product "Kb Support" | <= 1.5.88 Search vendor "Liquidweb" for product "Kb Support" and version " <= 1.5.88" | wordpress |
Affected
|