← WordPress Vulnerabilities
WordPress security by component

Awesome Support

Awesome Support adds customer support ticketing, user communication, agent management, and support workflow features to WordPress.

Awesome Support (awesome-support) is a WordPress plugin with 28 published CVE records in this archive. The latest tracked vulnerability was published Sep 09, 2026; the highest published CVSS base score is 8.8.

Plugin slug: awesome-support

CVE-2026-19946: Awesome Support lets subscribers deny other users' moderated activation

Awesome Support through 6.3.9 omits the edit_users or target-specific edit_user capability check in wpas_do_mr_deny_user(), relying only on a nonce not bound to the target account. A Subscriber or higher-privileged user holding that nonce can set mr_user_denied on another user, including an Administrator, blocking moderated activation and sending a denial email.

PublishedSep 09, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for awesome-support
Safe version
Sep 09, 2026 CVE-2026-19946
Awesome Support lets subscribers deny other users' moderated activation
Awesome Support through 6.3.9 omits the edit_users or target-specific edit_user capability check in wpas_do_mr_deny_user(), relying only on a nonce not bound to the target account. A Subscriber or higher-privileged user holding that nonce can set mr_user_denied on another user, including an Administrator, blocking moderated activation and sending a denial email.
See mitigation notes
CVE4.3
NVDPending
Apr 08, 2026 CVE-2026-4654
Awesome Support – WordPress HelpDesk & Support Plugin: Broken access control
Awesome Support – WordPress HelpDesk & Support Plugin is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is <= 6.3.7.
See mitigation notes
CVE5.3
NVDPending
Jan 16, 2026 CVE-2025-12641
Awesome Support - WordPress HelpDesk & Support: A security weakness
Awesome Support - WordPress HelpDesk & Support is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Sep 22, 2025 CVE-2025-58662
Awesome Support: Code execution
Awesome Support is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE7.2
NVDPending
Sep 09, 2025 CVE-2025-53340
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Apr 01, 2025 CVE-2024-13567
Awesome Support – WordPress HelpDesk & Support Plugin: Sensitive information exposure
Awesome Support – WordPress HelpDesk & Support Plugin is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE7.5
NVDPending
Dec 13, 2024 CVE-2024-54289
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Dec 09, 2024 CVE-2023-49857
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVD6.5
Dec 09, 2024 CVE-2023-49757
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Dec 09, 2024 CVE-2023-48324
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jun 12, 2024 CVE-2023-51537
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD7.3
Jun 10, 2024 CVE-2024-35741
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD8.8
Jun 09, 2024 CVE-2024-24716
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVD5.4
Jun 09, 2024 CVE-2024-30539
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD9.8
Feb 10, 2024 CVE-2024-0596
Awesome Support – WordPress HelpDesk & Support Plugin: A security weakness
Awesome Support – WordPress HelpDesk & Support Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVD5.3
Feb 10, 2024 CVE-2024-0595
Awesome Support – WordPress HelpDesk & Support Plugin: A security weakness
Awesome Support – WordPress HelpDesk & Support Plugin is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Feb 10, 2024 CVE-2024-0594
Awesome Support – WordPress HelpDesk & Support Plugin: SQL injection
Awesome Support – WordPress HelpDesk & Support Plugin is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.8
NVD8.8
Jan 05, 2024 CVE-2023-51538
Awesome Support – WordPress HelpDesk & Support Plugin: Cross-site request forgery
Awesome Support – WordPress HelpDesk & Support Plugin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Nov 30, 2023 CVE-2023-48323
Awesome Support – WordPress HelpDesk & Support Plugin: Cross-site request forgery
Awesome Support – WordPress HelpDesk & Support Plugin is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD8.8
Nov 06, 2023 CVE-2023-5355
Awesome Support: Arbitrary file deletion
Awesome Support is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable.
See mitigation notes
CVE8.1
NVD8.1
Nov 06, 2023 CVE-2023-5354
Awesome Support: Cross-site scripting
Awesome Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Nov 06, 2023 CVE-2023-5352
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 28, 2022 CVE-2022-3511
Awesome Support: Broken access control
Awesome Support is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE6.5
NVD6.5
Sep 21, 2022 CVE-2022-38073
Awesome Support: Cross-site scripting
Awesome Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVD5.4
Nov 26, 2021 CVE-2021-36919
Awesome Support: Cross-site scripting
Awesome Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD5.4
Jan 09, 2020 CVE-2019-20181
Awesome Support: Cross-site scripting
Awesome Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD4.8
Aug 20, 2019 CVE-2015-9318
Awesome Support: A security weakness
Awesome Support is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVEPending
NVD7.5
Aug 20, 2019 CVE-2015-9317
Awesome Support: Cross-site scripting
Awesome Support is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVEPending
NVD6.1