Missing Authorization in Awesome Support Plugin for WordPress
CVE-2026-19946

4.3MEDIUM

What is CVE-2026-19946?

The Awesome Support plugin for WordPress has a vulnerability that allows authenticated users with subscriber-level access or higher to execute unauthorized actions. Specifically, the function wpas_do_mr_deny_user() lacks proper capability checks, enabling these users to set the mr_user_denied flag on any user account, including administrators. This oversight could lead to permanent blocking of accounts from moderated activation and trigger denial notifications to affected users, posing significant security risks to WordPress sites using this plugin.

Affected Version(s)

Awesome Support – WordPress HelpDesk & Support Plugin 0 <= 6.3.9

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.