Support Board <= 3.8.0 - Unauthenticated Authorization Bypass due to Use of Default Secret Key

2025-07-08 10:43
Foxyyy

Strategic Overview

Status
Patched in 3.8.1
Affected PluginSupport Board
Affected Version<= 3.8.0
CVSS9.8Critical
CVECVE-2025-4855
View all Support Board vulnerabilities

Vulnerability Overview

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.

Technical Analysis

REMEDIATION: Update to version 3.8.1, or a newer patched version --- IDENTIFIER: CWE-639 (Authorization Bypass Through User-Controlled Key) The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C