vulnerability

WordPress Plugin: kb-support: CVE-2023-37890: Missing Authorization

Severity
4
CVSS
(AV:N/AC:L/Au:S/C:P/I:N/A:N)
Published
Jul 11, 2023
Added
May 15, 2025
Modified
May 15, 2025

Description

The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access or higher to extract sensitive data including customer data including name, email, phone number.

Solution

kb-support-plugin-cve-2023-37890
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.