216.73.216.226

CVE-2024-13604

· Published 05/04/2025 02:15 · Modified 05/04/2025 02:15

Labels: CVE-2024-13604 2025-04-05CVE-2024-13604CWE-200[email protected]

Essential information

Published
05/04/2025 02:15
Modified
05/04/2025 02:15
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS metrics

Description

The KB Support – Customer Support Ticket & Helpdesk Plugin, Knowledge Base Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.4 via the 'kbs' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/kbs directory which can contain file attachments included in support tickets. The vulnerability was partially patched in version 1.7.3.2.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / kbsupport cpe:2.3:a:wordpress:kbsupport:*:*:*:*:*:wordpress:*:*
wordpress / knowledge base plugin cpe:2.3:a:wordpress:knowledge_base_plugin:*:*:*:*:*:wordpress:*:*

References