Extension WordPress
Vulnérabilités Awesome Support – WordPress HelpDesk & Support Plugin
Cette page rassemble les failles publiées pour Awesome Support – WordPress HelpDesk & Support Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Awesome Support – WordPress HelpDesk & Support Plugin
27 fiches
Awesome Support <= 6.3.7 – Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax() function failing to verify whether the…
*-6.3.7
6.3.8
07/04/2026
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 – Missing Authorization to Unauthenticated Role Demotion
The Awesome Support – WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the 'wpas_do_mr_activate_user' function not verifying…
*-6.3.6
6.3.7
15/01/2026
Awesome Support <= 6.3.5 – Authenticated (Support Manager+) PHP Object Injection
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.3.5 via deserialization of untrusted input. This makes it possible for authenticated attackers,…
*-6.3.5
6.3.6
22/09/2025
Awesome Support <= 6.3.6 – Information Exposure
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.6. This makes it possible for unauthenticated attackers to extract sensitive user or…
*-6.3.6
6.3.7
14/08/2025
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 – Unauthenticated Sensitive Information Exposure Through Unprotected Directory
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes it possible for unauthenticated attackers to…
*-6.3.1
6.3.2
31/03/2025
Awesome Support <= 6.3.1 – Missing Authorization
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 6.3.1. This makes it possible…
*-6.3.1
6.3.2
11/12/2024
Awesome Support <= 6.1.7 – Missing Authorization
The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in versions up to, and including, 6.1.7. This makes it possible for unauthenticated attackers to perform unauthorized actions.
*-6.1.7
6.1.8
29/03/2024
Awesome Support <= 6.1.6 – Insufficient Authorization via wpas_can_delete_attachments()
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability check in the wpas_can_delete_attachments() function in all versions up to, and including 6.1.6. This…
*-6.1.6
6.1.7
12/03/2024
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Missing Authorization via wpas_get_users()
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7.…
*-6.1.7
6.1.8
09/02/2024
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Missing Authorization via editor_html()
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This…
*-6.1.7
6.1.8
09/02/2024
Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 – Authenticated (Subscriber+) SQL Injection
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping…
*-6.1.7
6.1.8
09/02/2024
Awesome Support <= 6.1.5 – Cross-Site Request Forgery
The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.5. This is due to missing or incorrect nonce validation on the wpas_get_ticket_replies_ajax and ajax_delete_attachment functions. This makes it possible…
*-6.1.5
6.1.6
27/12/2023
Awesome Support <= 6.1.5 – Missing Authorization via wpas_load_reply_history
The Awesome Support plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the wpas_load_reply_history function in versions up to, and including, 6.1.5. This makes it possible for unauthenticated attackers to…
*-6.1.5
6.1.6
27/12/2023
Awesome Support <= 6.1.7 – Missing Authorization
The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 6.1.7. This makes it possible for unauthenticated attackers to perform an unauthorized…
*-6.1.7
6.1.8
07/12/2023
Awesome Support <= 6.1.10 – Missing Authorization
The Awesome Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 6.1.10. This makes it possible for authenticated attackers, with subscriber-level access…
*-6.1.10
6.1.11
04/12/2023
Awesome Support <= 6.1.4 – Cross-Site Request Forgery via wpas_edit_reply_ajax()
The Awesome Support plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.1.4. This is due to missing or incorrect nonce validation on the wpas_edit_reply_ajax() function. This makes it possible for unauthenticated…
*-6.1.4
6.1.5
23/11/2023
Awesome Support <= 6.1.4 – Missing Authorization via wpas_edit_reply_ajax()
The Awesome Support plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply_ajax() function in versions up to, and including, 6.1.4. This makes it possible for authenticated attackers, with…
*-6.1.4
6.1.5
23/11/2023
Awesome Support <= 6.1.4 – Authenticated (Submitter+) Arbitrary File Deletion
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 6.1.4. This is due to insufficient controls on paths being supplied when a…
*-6.1.4
6.1.5
16/10/2023
Awesome Support <= 6.1.4 – Reflected Cross-Site Scripting
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post' parameter in all versions up to, and including, 6.1.4 due to insufficient input sanitization and output escaping.…
*-6.1.4
6.1.5
16/10/2023
Awesome Support <= 6.1.4 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpas_edit_reply function in all versions up to, and including, 6.1.4. This…
*-6.1.4
6.1.5
16/10/2023
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.