Security Advisory

CVE-2025-4855

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-07-08 23:22:49
Last updated 2026-04-08 17:15:40
Assigner Wordfence
State PUBLISHED

Description

The Support Board plugin for WordPress is vulnerable to unauthorized access/modification/deletion of data due to use of hardcoded default secrets in the sb_encryption() function in all versions up to, and including, 3.8.0. This makes it possible for unauthenticated attackers to bypass authorization and execute arbitrary AJAX actions defined in the sb_ajax_execute() function. An attacker can use this vulnerability to exploit CVE-2025-4828 and various other functions unauthenticated.