Sensitive Information Exposure in KB Support Plugin for WordPress
CVE-2024-13604
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 April 2025
What is CVE-2024-13604?
The KB Support – Customer Support Ticket & Helpdesk Plugin for WordPress is susceptible to a sensitive information exposure flaw. This vulnerability affects all versions up to and including 1.7.4 and arises from the insecure storage of sensitive data within the '/wp-content/uploads/kbs' directory. Attackers without authentication can exploit this vulnerability to extract potentially sensitive information stored in file attachments associated with support tickets. Although a partial patch was introduced in version 1.7.3.2, it is essential for users to upgrade to the latest version to mitigate this exposure effectively.
Affected Version(s)
KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin * <= 1.7.4