Access violation vulnerability in KB Support – WordPress Help Desk 1.5.88

The KB Support plugin for WordPress is vulnerable to a security risk which can potentially allow attackers with certain permissions to access sensitive information about customers. This includes their names, emails, and phone numbers. The vulnerability only affects versions up to and including 1.5.88 and is due to the lack of a capability check in the kbs_ajax_get_customer_data function.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.