Description
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version
Timeline
| 2025-05-15: | Discovered |
| 2025-07-07: | Vendor Notified |
| 2025-07-08: | Disclosed |
Credits
Friderika Baranyai
References
www.wordfence.com/...-d490-4a3e-97fc-70cf008cbf66?source=cve
codecanyon.net/.../support-board-help-desk-and-chat/20359943