Unauthenticated Privilege Escalation in Support Board Plugin by WordPress
CVE-2026-27395
9.8CRITICAL
What is CVE-2026-27395?
The Support Board plugin for WordPress is affected by a vulnerability that allows unauthenticated users to escalate their privileges. This flaw exists in versions prior to 3.8.9, enabling potential attackers to perform actions that should require authentication, thereby compromising the security of the site.
Affected Version(s)
Support Board < 3.8.9