Sensitive Information Exposure in KB Support Plugin for WordPress
CVE-2024-13604

7.5HIGH

What is CVE-2024-13604?

The KB Support – Customer Support Ticket & Helpdesk Plugin for WordPress is susceptible to a sensitive information exposure flaw. This vulnerability affects all versions up to and including 1.7.4 and arises from the insecure storage of sensitive data within the '/wp-content/uploads/kbs' directory. Attackers without authentication can exploit this vulnerability to extract potentially sensitive information stored in file attachments associated with support tickets. Although a partial patch was introduced in version 1.7.3.2, it is essential for users to upgrade to the latest version to mitigate this exposure effectively.

Affected Version(s)

KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin * <= 1.7.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.