Executive brief
Support Board is a WordPress plugin used to manage customer support and chat communications. A critical security flaw allows unauthorized individuals to gain administrative access to the website without needing a password. This could lead to a total takeover of the site, allowing attackers to steal customer data, modify content, or shut down services.
Technical details
The Support Board plugin for WordPress contains a privilege escalation vulnerability (CWE-266) in versions prior to 3.8.9. The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the WordPress site. The root cause is an incorrect privilege assignment within the plugin's logic. An attacker can exploit this over the network without any user interaction or existing account. A patch is available in version 3.8.9.
Affected products
- Schiocco Support Board < 3.8.9
Timeline
- 2025-11-13: other: Reported by researcher Phat RiO
- 2026-06-01: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date