PT-2025-15048 · WordPress · The Kb Support – Customer Support Ticket & Helpdesk Plugin

Tim Coen

·

Published

2025-04-05

·

Updated

2025-04-05

·

CVE-2024-13604

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress versions up to, and including, 1.7.4
Description The issue allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory, which can contain file attachments included in support tickets. This is possible due to sensitive information exposure via the 'kbs' directory.
Recommendations For versions up to, and including, 1.7.4, update to a version that fully addresses the sensitive information exposure issue, as version 1.7.3.2 only partially patches the vulnerability. As a temporary workaround, consider restricting access to the /wp-content/uploads/kbs directory to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-13604

Affected Products

The Kb Support – Customer Support Ticket & Helpdesk Plugin