« Volver al listado

Awesomesupport

Awesomesupport Awesome Support: vulnerabilidades y CVE

Awesomesupport Awesome Support tiene 9 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses5
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-96268Media (6.4)0.20%—1 oct 2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient…
CVE-2026-96820Alta (7.1)0.24%—30 sept 2026
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
CVE-2026-19946Media (4.3)0.24%—9 sept 2026
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its…
CVE-2026-4654Media (5.3)0.44%—8 abr 2026
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 6.3.7. This is due to the wpas_get_ticket_replies_ajax()…
CVE-2025-12641Media (6.5)0.40%—16 ene 2026
The Awesome Support - WordPress HelpDesk & Support Plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in all versions up to, and including, 6.3.6. This is due to the…
CVE-2025-58662Alta (7.2)0.47%—22 sept 2025
Deserialization of Untrusted Data vulnerability in awesomesupport Awesome Support awesome-support allows Object Injection.This issue affects Awesome Support: from n/a through <= 6.3.5.
CVE-2025-53340Media (5.3)0.29%—9 sept 2025
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Retrieve Embedded Sensitive Data.This issue affects Awesome Support: from n/a through <= 6.3.6.
CVE-2024-13567Alta (7.5)0.65%—1 abr 2025
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 6.3.1 via the 'awesome-support' directory. This makes…
CVE-2024-54289Media (6.5)0.60%—13 dic 2024
Missing Authorization vulnerability in awesomesupport Awesome Support awesome-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Awesome Support: from n/a through <= 6.3.1.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059.007 JavaScript2
  2. T1190 Exploit Public-Facing Application2
  3. T1005 Data from Local System1
  4. T1059 Command and Scripting Interpreter1
  5. T1189 Drive-by Compromise1
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Awesomesupport