๐Ÿ” CVE Alert

CVE-2025-4855

CRITICAL 9.8

Support Board <= 3.8.0 - Unauthenticated Authorization Bypass due to Use of Default Secret Key

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.

CWE CWE-639
Vendor schiocco
Product support board
Published Jul 8, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for schiocco support board

Be the first to know when new critical vulnerabilities affecting schiocco support board are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Schiocco / Support Board
0 โ‰ค 3.8.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/afd48bc8-d490-4a3e-97fc-70cf008cbf66?source=cve codecanyon.net: https://codecanyon.net/item/support-board-help-desk-and-chat/20359943

Credits

Friderika Baranyai