Security readout for executives and security teams
Plain-English summary
CVE-2024-33589 is a broken access control issue in the WordPress KB Support plugin through version 1.6.0. A logged-in attacker may be able to access sensitive information they should not see. The cited CVSS score is medium, but confidentiality impact is high.
Executive priority
Handle in the normal vulnerability remediation cycle, with higher priority for sites exposing customer support data or allowing broad user registration. The main business concern is unauthorized disclosure, not site takeover based on the provided sources.
Technical view
The vulnerability is CWE-862 Missing Authorization in WPOmnia KB Support for WordPress, package name kb-support, through 1.6.0. CVSS 3.1 is 6.5: network reachable, low complexity, low privileges required, no user interaction, unchanged scope, high confidentiality impact, no integrity or availability impact.
Likely exposure
Exposure is limited to WordPress sites running KB Support versions through 1.6.0. The CVSS vector indicates attackers need some authenticated access, so public self-registration, shared accounts, or broad contributor/customer access can increase practical risk.
Exploitation context
The source bundle does not show CISA KEV listing or cited evidence of active exploitation. It also does not provide exploit availability or vulnerable endpoint details. Treat this as a confidentiality-focused authorization flaw until vendor guidance gives more specifics.
Researcher notes
Evidence is thin beyond the CVE and Patchstack listing. The CVSS vector supports authenticated, network-based, low-complexity access with high confidentiality impact. Do not assume unauthenticated exploitation, integrity impact, or a specific patch level unless confirmed by vendor or Patchstack data.
Mitigation direction
- Inventory WordPress sites for the KB Support plugin and recorded version.
- Check WPOmnia or Patchstack guidance for an updated fixed release.
- Update the plugin if a fixed version is available from the vendor.
- Disable or remove the plugin where it is unnecessary or unmaintained.
- Reduce untrusted WordPress accounts and review self-registration settings.
Validation and detection
- Confirm whether KB Support is installed and whether the version is 1.6.0 or older.
- Review WordPress roles with access to KB Support functionality or customer data.
- Check access logs for unusual authenticated requests around KB Support features.
- Verify remediation by confirming the plugin is updated, disabled, or removed.
- Document any exception where the plugin must remain active.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-862: Authorization and privilege behavior lookup
Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2024-33589 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 6.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N2.83.6Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
6.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source materials
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Missing Authorization
Missing Authorization represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
