What the vulnerability does
01Description
Missing Authorization vulnerability in WPOmnia KB Support – WordPress Help Desk and Knowledge Base allows Accessing Functionality Not Properly Constrained by ACLs. Users with a role as low as a subscriber can view other customers.This issue affects KB Support – WordPress Help Desk and Knowledge Base: from n/a through 1.5.88.
Explanation of Vulnerability in Simple Terms
02Summary
The KB Support plugin for WordPress does not properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive information they should not have access to. The vulnerability affects versions up to 1.5.88. Update the plugin to a version newer than 1.5.88.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the help desk or knowledge base that should be restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Confidential help desk tickets, knowledge base articles, or user data may be exposed to low-privilege site users.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
November 30, 2023
CVE published
April 28, 2026
Record updated