Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20754 | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated. |
Mon, 14 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Schiocco
Schiocco support Board |
|
| CPEs | cpe:2.3:a:schiocco:support_board:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Schiocco
Schiocco support Board |
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 09 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated. | |
| Title | Support Board <= 3.8.0 - Unauthenticated Authorization Bypass due to Use of Default Secret Key | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:15:40.803Z
Reserved: 2025-05-16T17:00:48.567Z
Link: CVE-2025-4855
Updated: 2025-07-09T13:14:55.489Z
Status : Analyzed
Published: 2025-07-09T00:15:47.243
Modified: 2025-07-14T15:10:54.030
Link: CVE-2025-4855
No data.
OpenCVE Enrichment
Updated: 2026-04-20T22:30:19Z
EUVD