CVE-2025-4855
Support Board <= 3.8.0 - Unauthenticated Authorization Bypass due to Use of Default Secret Key
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.
| CWE | CWE-639 |
| Vendor | schiocco |
| Product | support board |
| Published | Jul 8, 2025 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for schiocco support board
Be the first to know when new critical vulnerabilities affecting schiocco support board are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Schiocco / Support Board
0 โค 3.8.0
References
Credits
Friderika Baranyai