LOGON records
6 published records for vendor logon.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-862 Missing Authorization4
- CWE-1236 Improper Neutralization of Formula Elements in a CSV File1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2023-25983No exploit | WordPress KB Support Plugin <= 1.5.84 is vulnerable to CSV Injectionlogon · kb support · CWE-1236 | High8.8 | — | 1.1% | Nov 7, 2023 |
32Monitor | CVE-2024-8548No exploit | KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actionslogon · kb support · CWE-862 | High8.1 | — | 0.4% | Oct 1, 2024 |
26Monitor | CVE-2024-33589No exploit | WordPress KB Support plugin <= 1.6.0 - Broken Access Control vulnerabilitylogon · kb support · CWE-862 | Medium6.5 | — | 0.5% | Apr 29, 2024 |
26Monitor | CVE-2024-8632No exploit | KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposurelogon · kb support · CWE-862 | Medium6.5 | — | 0.3% | Oct 1, 2024 |
24Monitor | CVE-2025-24741No exploit | WordPress KB Support plugin <= 1.6.7 - Open Redirection vulnerabilitylogon · kb support · CWE-601 | Medium6.1 | — | 0.2% | Jan 27, 2025 |
17Monitor | CVE-2023-37890No exploit | WordPress KB Support Plugin <= 1.5.88 is vulnerable to Broken Access Controllogon · kb support · CWE-862 | Medium4.3 | — | 0.5% | Nov 30, 2023 |
- CVE-2023-2598335Monitor
WordPress KB Support Plugin <= 1.5.84 is vulnerable to CSV Injection
HighCVSS 8.8No exploitEPSS 1%logon · kb supportNov 7, 2023
- CVE-2024-854832Monitor
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Authenticated (Subscriber+) Multiple Administrator Actions
HighCVSS 8.1No exploitEPSS 0%logon · kb supportOct 1, 2024
- CVE-2024-3358926Monitor
WordPress KB Support plugin <= 1.6.0 - Broken Access Control vulnerability
MediumCVSS 6.5No exploitEPSS 0%logon · kb supportApr 29, 2024
- CVE-2024-863226Monitor
KB Support – WordPress Help Desk and Knowledge Base <= 1.6.6 - Missing Authorization to Unauthenticated Ticket Reply Exposure
MediumCVSS 6.5No exploitEPSS 0%logon · kb supportOct 1, 2024
- CVE-2025-2474124Monitor
WordPress KB Support plugin <= 1.6.7 - Open Redirection vulnerability
MediumCVSS 6.1No exploitEPSS 0%logon · kb supportJan 27, 2025
- CVE-2023-3789017Monitor
WordPress KB Support Plugin <= 1.5.88 is vulnerable to Broken Access Control
MediumCVSS 4.3No exploitEPSS 1%logon · kb supportNov 30, 2023