Rapid7

vulnerability

WordPress Plugin: kb-support: CVE-2023-37890: Missing Authorization

Severity
5
CVSS
(AV:N/AC:L/Au:S/C:P/I:P/A:N)
Published
Jul 11, 2023
Added
May 15, 2025
Modified
May 5, 2026

Description

The KB Support plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.5.88 via the kbs_ajax_get_customer_data function due to lack of a capability check. This can allow authenticated attackers with subscriber access or higher to extract sensitive data including customer data including name, email, phone number.

Solution

kb-support-plugin-cve-2023-37890
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.