Extension WordPress

Vulnérabilités Awesome Support – WordPress HelpDesk & Support Plugin

Cette page rassemble les failles publiées pour Awesome Support – WordPress HelpDesk & Support Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.

27Vulnérabilités
0Critiques
27Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de Awesome Support – WordPress HelpDesk & Support Plugin

27 fiches

CVE-2026-4654 Moyenne · 5,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.3.7 – Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the…

Versions affectées

*-6.3.7

Correctif

6.3.8

Publication

07/04/2026

CVE-2025-12641 Moyenne · 6,5
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 – Missing Authorization to Unauthenticated Role Demotion

The Awesome Support – WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying…

Versions affectées

*-6.3.6

Correctif

6.3.7

Publication

15/01/2026

CVE-2025-58662 Élevée · 7,5
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.3.5 – Authenticated (Support Manager+) PHP Object Injection

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers,…

Versions affectées

*-6.3.5

Correctif

6.3.6

Publication

22/09/2025

CVE-2024-13567 Élevée · 7,5
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to…

Versions affectées

*-6.3.1

Correctif

6.3.2

Publication

31/03/2025

CVE-2024-24716 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.6 – Insufficient Authorization via wpas_can_delete_attachments()

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check in the wpas_can_delete_attachments() function in all versions up to, and including 6.1.6. This…

Versions affectées

*-6.1.6

Correctif

6.1.7

Publication

12/03/2024

CVE-2024-0595 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Missing Authorization via wpas_get_users()

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7.…

Versions affectées

*-6.1.7

Correctif

6.1.8

Publication

09/02/2024

CVE-2024-0596 Moyenne · 5,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Missing Authorization via editor_html()

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This…

Versions affectées

*-6.1.7

Correctif

6.1.8

Publication

09/02/2024

CVE-2024-0594 Élevée · 8,8
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Authenticated (Subscriber+) SQL Injection

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping…

Versions affectées

*-6.1.7

Correctif

6.1.8

Publication

09/02/2024

CVE-2023-51538 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.5 – Cross-Site Request Forgery

The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. This is due to missing or incorrect nonce validation on the wpas_get_ticket_replies_ajax and ajax_delete_attachment functions. This makes it possible…

Versions affectées

*-6.1.5

Correctif

6.1.6

Publication

27/12/2023

CVE-2023-51537 Moyenne · 5,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.5 – Missing Authorization via wpas_load_reply_history

The Awesome Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpas_load_reply_history function in versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to…

Versions affectées

*-6.1.5

Correctif

6.1.6

Publication

27/12/2023

CVE-2023-48323 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.4 – Cross-Site Request Forgery via wpas_edit_reply_ajax()

The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.4. This is due to missing or incorrect nonce validation on the wpas_edit_reply_ajax() function. This makes it possible for unauthenticated…

Versions affectées

*-6.1.4

Correctif

6.1.5

Publication

23/11/2023

CVE-2023-48324 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.4 – Missing Authorization via wpas_edit_reply_ajax()

The Awesome Support plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply_ajax() function in versions up to, and including, 6.1.4. This makes it possible for authenticated attackers, with…

Versions affectées

*-6.1.4

Correctif

6.1.5

Publication

23/11/2023

CVE-2023-5354 Moyenne · 6,1
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.4 – Reflected Cross-Site Scripting

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping.…

Versions affectées

*-6.1.4

Correctif

6.1.5

Publication

16/10/2023

CVE-2023-5352 Moyenne · 4,3
Awesome Support – WordPress HelpDesk & Support Plugin

Awesome Support <= 6.1.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification

The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply function in all versions up to, and including, 6.1.4. This…

Versions affectées

*-6.1.4

Correctif

6.1.5

Publication

16/10/2023

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités