Support Board Plugin: Unauthenticated Privilege Escalation (CVSS 9.8)

Introduction

Support Board, a popular live chat and helpdesk plugin, had a critical unauthenticated privilege escalation vulnerability disclosed on June 1, 2026, rated CVSS 9.8. Versions before 3.8.9 let an attacker with no account and no login create or take over an administrator account directly — a straight path to full site control.

What You Should Do Right Now

  1. Check your installed version under Plugins in wp-admin. Anything before 3.8.9 is affected.
  2. Back up your site first, then update the plugin — if the site has already been touched, you want a snapshot of the current state before you start changing things.
  3. Update to 3.8.9 or later immediately.
  4. Audit your admin user list for any account you don’t recognize, especially ones created recently. Remove anything suspicious after confirming with your team.

Why Privilege Escalation Bugs Are Especially Dangerous

Unlike a crash or a broken feature, privilege escalation often leaves no visible trace — the site keeps working normally while an attacker quietly holds admin access in the background. That’s exactly why checking your user list matters as much as updating the plugin, and why having recent backups from before the disclosure date gives you something trustworthy to compare against or roll back to if you find an account you don’t recognize.

FAQ

How do I know if I’ve already been compromised?
Check Users in wp-admin for unfamiliar administrator accounts, and review recently modified files if your host or security plugin offers a file-change log.

Is updating enough, or do I need to do more?
Updating closes the hole, but if the site was already exploited before you patched, you’ll also need to remove any rogue admin accounts and consider a full malware scan.

What if I can’t update right away?
Deactivate the plugin temporarily rather than leaving a known-critical, unauthenticated flaw exposed.

Conclusion

A 9.8-severity, no-login-required privilege escalation bug is as urgent as it gets. Back up, update, then check who has admin access.

Have a clean restore point before every update

Nota Backup & Restore lets you take a full backup in minutes and restore it even if wp-admin is compromised. Start your 14-day free trial — no credit card required.