plugin

Awesome Support Vulnerabilities

57 known security issues reported for the Awesome Support WordPress plugin. Most recent disclosed Apr 7, 2026.

5 high 22 medium

Running Awesome Support on your site? Check whether your installed version is affected.

Scan your site free

Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the authenticated user has permission to view the specific ticket...

CVSS:
5.3
Affected:
up to 6.3.7
Fixed in:
6.3.8
Disclosed:
Apr 7, 2026

CVE-2026-4654 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.3.7

unknown

[en] The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles, c...

Affected:
up to 6.3.7
Fixed in:
6.3.7
Disclosed:
Jan 16, 2026

CVE-2025-12641 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion

medium

The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying that a user has permission to modify other users' roles, combin...

CVSS:
6.5
Affected:
up to 6.3.6
Fixed in:
6.3.7
Disclosed:
Jan 15, 2026

CVE-2025-12641 on NVD →

Awesome Support <= 6.3.5 - Authenticated (Support Manager+) PHP Object Injection

high

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers, with Custom-level access and above, to inject a PHP Object. No know...

CVSS:
7.5
Affected:
up to 6.3.5
Fixed in:
6.3.6
Disclosed:
Sep 22, 2025

CVE-2025-58662 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] <= 6.3.4 (unfixed)

unknown

[en] Missing Authorization vulnerability in awesomesupport Awesome Support. This issue affects Awesome Support: from n/a through 6.3.4.

Affected:
up to 6.3.4
Fix:
No patched version reported
Disclosed:
Sep 9, 2025

CVE-2025-53340 on NVD →

Awesome Support <= 6.3.6 - Information Exposure

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.6. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.

CVSS:
5.3
Affected:
up to 6.3.6
Fixed in:
6.3.7
Disclosed:
Aug 14, 2025

CVE-2025-53340 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.3.2

unknown

[en] The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp...

Affected:
up to 6.3.2
Fixed in:
6.3.2
Disclosed:
Apr 1, 2025

CVE-2024-13567 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory

high

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-cont...

CVSS:
7.5
Affected:
up to 6.3.1
Fixed in:
6.3.2
Disclosed:
Mar 31, 2025

CVE-2024-13567 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.3.2

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.3.0.

Affected:
up to 6.3.2
Fixed in:
6.3.2
Disclosed:
Dec 13, 2024

CVE-2024-54289 on NVD →

Awesome Support <= 6.3.1 - Missing Authorization

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unaut...

CVSS:
4.3
Affected:
up to 6.3.1
Fixed in:
6.3.2
Disclosed:
Dec 11, 2024

CVE-2024-54289 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.7.

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Dec 9, 2024

CVE-2023-49857 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.11

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.10.

Affected:
up to 6.1.11
Fixed in:
6.1.11
Disclosed:
Dec 9, 2024

CVE-2023-49757 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.5

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through 6.1.4.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Dec 9, 2024

CVE-2023-48324 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.6

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.5.

Affected:
up to 6.1.6
Fixed in:
6.1.6
Disclosed:
Jun 12, 2024

CVE-2023-51537 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Jun 10, 2024

CVE-2024-35741 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.7

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.6.

Affected:
up to 6.1.7
Fixed in:
6.1.7
Disclosed:
Jun 9, 2024

CVE-2024-24716 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] Missing Authorization vulnerability in Awesome Support Team Awesome Support.This issue affects Awesome Support: from n/a through 6.1.7.

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Jun 9, 2024

CVE-2024-30539 on NVD →

Awesome Support <= 6.1.7 - Missing Authorization

medium

The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 6.1.7. This makes it possible for unauthenticated attackers to perform unauthorized actions.

CVSS:
5.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Mar 29, 2024

CVE-2024-30539 on NVD →

Awesome Support <= 6.1.6 - Insufficient Authorization via wpas_can_delete_attachments()

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check in the wpas_can_delete_attachments() function in all versions up to, and including 6.1.6. This makes it possible for authenticated attackers, with sub...

CVSS:
4.3
Affected:
up to 6.1.6
Fixed in:
6.1.7
Disclosed:
Mar 12, 2024

CVE-2024-24716 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Feb 10, 2024

CVE-2024-0594 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access a...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Feb 10, 2024

CVE-2024-0596 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.8

unknown

[en] The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-lev...

Affected:
up to 6.1.8
Fixed in:
6.1.8
Disclosed:
Feb 10, 2024

CVE-2024-0595 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection

high

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the e...

CVSS:
8.8
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Feb 9, 2024

CVE-2024-0594 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html()

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and ab...

CVSS:
5.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Feb 9, 2024

CVE-2024-0596 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via wpas_get_users()

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level ac...

CVSS:
4.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Feb 9, 2024

CVE-2024-0595 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.6

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.5.

Affected:
up to 6.1.6
Fixed in:
6.1.6
Disclosed:
Jan 5, 2024

CVE-2023-51538 on NVD →

Awesome Support <= 6.1.5 - Missing Authorization via wpas_load_reply_history

medium

The Awesome Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpas_load_reply_history function in versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to load reply history.

CVSS:
5.3
Affected:
up to 6.1.5
Fixed in:
6.1.6
Disclosed:
Dec 27, 2023

CVE-2023-51537 on NVD →

Awesome Support <= 6.1.5 - Cross-Site Request Forgery

medium

The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. This is due to missing or incorrect nonce validation on the wpas_get_ticket_replies_ajax and ajax_delete_attachment functions. This makes it possible for unauthenticated attackers to trigger the...

CVSS:
4.3
Affected:
up to 6.1.5
Fixed in:
6.1.6
Disclosed:
Dec 27, 2023

CVE-2023-51538 on NVD →

Awesome Support <= 6.1.7 - Missing Authorization

medium

The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.1.7. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 6.1.7
Fixed in:
6.1.8
Disclosed:
Dec 7, 2023

CVE-2023-49857 on NVD →

Awesome Support <= 6.1.10 - Missing Authorization

medium

The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 6.1.10. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
5.4
Affected:
up to 6.1.10
Fixed in:
6.1.11
Disclosed:
Dec 4, 2023

CVE-2023-49757 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.5

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Awesome Support Team Awesome Support – WordPress HelpDesk & Support Plugin allows Cross Site Request Forgery.This issue affects Awesome Support – WordPress HelpDesk & Support Plugin: from n/a through 6.1.4.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Nov 30, 2023

CVE-2023-48323 on NVD →

Awesome Support <= 6.1.4 - Cross-Site Request Forgery via wpas_edit_reply_ajax()

medium

The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.4. This is due to missing or incorrect nonce validation on the wpas_edit_reply_ajax() function. This makes it possible for unauthenticated attackers to edit replies via a forged request granted the...

CVSS:
4.3
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Nov 23, 2023

CVE-2023-48323 on NVD →

Awesome Support <= 6.1.4 - Missing Authorization via wpas_edit_reply_ajax()

medium

The Awesome Support plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply_ajax() function in versions up to, and including, 6.1.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to edit replies.

CVSS:
4.3
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Nov 23, 2023

CVE-2023-48324 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.5

unknown

[en] The Awesome Support WordPress plugin before 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Nov 6, 2023

CVE-2023-5354 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.5

unknown

[en] The Awesome Support WordPress plugin before 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Nov 6, 2023

CVE-2023-5352 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.5

unknown

[en] The Awesome Support WordPress plugin before 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.

Affected:
up to 6.1.5
Fixed in:
6.1.5
Disclosed:
Nov 6, 2023

CVE-2023-5355 on NVD →

Awesome Support <= 6.1.4 - Authenticated (Submitter+) Arbitrary File Deletion

high

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 6.1.4. This is due to insufficient controls on paths being supplied when a user deletes an attachment from a ticket. This makes it possible for authenticated atta...

CVSS:
8.1
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Oct 16, 2023

CVE-2023-5355 on NVD →

Awesome Support <= 6.1.4 - Reflected Cross-Site Scripting

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject a...

CVSS:
6.1
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Oct 16, 2023

CVE-2023-5354 on NVD →

Awesome Support <= 6.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification

medium

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply function in all versions up to, and including, 6.1.4. This makes it possible for authenticated attackers, with subscriber-level acces...

CVSS:
4.3
Affected:
up to 6.1.4
Fixed in:
6.1.5
Disclosed:
Oct 16, 2023

CVE-2023-5352 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.1.2

unknown

[en] The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector

Affected:
up to 6.1.2
Fixed in:
6.1.2
Disclosed:
Nov 28, 2022

CVE-2022-3511 on NVD →

Awesome Support <= 6.1.1 - Insecure Direct Object Reference to (Subscriber+) Ticket Export

medium

The Awesome Support plugin for WordPress is vulnerable to Insecure Direct Object Reference to (Subscriber+) Ticket Export in versions up to, and including, 6.1.1. Improper protection of the 'file' parameter used to control the user id value during exported tickets archive downloads makes it possible for subscriber-leve...

CVSS:
4.3
Affected:
up to 6.1.1
Fixed in:
6.1.2
Disclosed:
Nov 7, 2022

CVE-2022-3511 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.0.8

unknown

[en] Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.

Affected:
up to 6.0.8
Fixed in:
6.0.8
Disclosed:
Sep 21, 2022

CVE-2022-38073 on NVD →

Awesome Support <= 6.0.7 - Authenticated Stored Cross-Site Scripting

high

The Awesome Support plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 6.0.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses...

CVSS:
7.2
Affected:
up to 6.0.7
Fixed in:
6.0.8
Disclosed:
Sep 14, 2022

CVE-2022-38073 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.6 - Reflected Cross-Site Scripting

medium

The "Awesome Support – WordPress HelpDesk & Support Plugin" plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters in versions up to, and including, 6.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit...

CVSS:
6.1
Affected:
up to 6.0.6
Fixed in:
6.0.7
Disclosed:
Nov 26, 2021

CVE-2021-36919 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.0.7

unknown

[en] Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities in WordPress Awesome Support plugin (versions <= 6.0.6), vulnerable parameters (&id, &assignee).

Affected:
up to 6.0.7
Fixed in:
6.0.7
Disclosed:
Nov 26, 2021

CVE-2021-36919 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.0.11

unknown

[en] The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues

Affected:
up to 6.0.11
Fixed in:
6.0.11
Disclosed:
Sep 6, 2021

CVE-2021-24435 on NVD →

Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting

medium

The iframe-font-preview.php file of the titan-framework does not properly escape the font-weight and font-family GET parameters before outputting them back in an href attribute, leading to Reflected Cross-Site Scripting issues.

CVSS:
6.1
Affected:
up to 6.0.10
Fixed in:
6.0.11
Disclosed:
Aug 9, 2021

CVE-2021-24435 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.0.9

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered by iohex and WPScanTeam in WordPress Awesome Support plugin (versions <= 6.0.8).

Affected:
up to 6.0.9
Fixed in:
6.0.9
Disclosed:
Aug 9, 2021

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 6.0.14

unknown

[en] The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.

Affected:
up to 6.0.14
Fixed in:
6.0.14
Disclosed:
Jan 9, 2020

CVE-2019-20181 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.13 - Cross-Site Scripting via post_title

medium

The awesome-support plugin 6.0.13 and below for WordPress allows XSS via the post_title parameter.

CVSS:
4.8
Affected:
up to 6.0.13
Fixed in:
6.0.14
Disclosed:
Jan 6, 2020

CVE-2019-20181 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 3.1.7

unknown

[en] The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.

Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
Aug 20, 2019

CVE-2015-9318 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 3.1.7

unknown

[en] The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.

Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
Aug 20, 2019

CVE-2015-9317 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 4.3.2

unknown

WordPress Awesome Support plugin Authenticated Arbitrary File Viewing Vulnerability exists in the function wpas_tools_log_viewer_view() accessible through WordPress’ AJAX functionality (in the file /includes/admin/functions-log-viewer.php):

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Oct 23, 2017

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] < 4.3.2

unknown

WordPress Awesome Support plugin Authenticated Arbitrary File Deletion Vulnerability exists in the function wpas_tools_log_viewer_delete() accessible to anyone logged in, by allowing access through WordPress’ AJAX functionality (in the file /includes/admin/functions-log-viewer.php):

Affected:
up to 4.3.2
Fixed in:
4.3.2
Disclosed:
Oct 23, 2017

Awesome Support – WordPress HelpDesk & Support Plugin <= 3.1.6 - Arbitrary Shortcode Execution

medium

The awesome-support plugin before 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.

CVSS:
6.5
Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
May 15, 2015

CVE-2015-9318 on NVD →

Awesome Support – WordPress HelpDesk & Support Plugin < 3.1.7 - Cross-Site Scripting

medium

The awesome-support plugin before 3.1.7 for WordPress has XSS via custom information messages.

CVSS:
6.1
Affected:
up to 3.1.7
Fixed in:
3.1.7
Disclosed:
May 15, 2015

CVE-2015-9317 on NVD →

Awesome Support &#8211; WordPress HelpDesk &amp; Support Plugin [awesome-support] <= 6.3.5 (unfixed)

unknown
Affected:
up to 6.3.5
Fix:
No patched version reported

CVE-2025-58662 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database