Stored Cross-Site Scripting in Awesome Support Plugin for WordPress
CVE-2026-96268
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-96268?
The Awesome Support plugin for WordPress is susceptible to Stored Cross-Site Scripting due to inadequate input sanitization and output escaping via the 'gdpr-data' parameter. This vulnerability enables authenticated attackers with subscriber-level access and above to inject arbitrary web scripts into pages. These scripts execute whenever a user accesses the compromised page. The AJAX handlers inadequately verify 'gdpr-user' IDs, allowing Subscriber-level users to manipulate the content and potentially exploit other accounts. The emitted nonce via wp_localize_script further exposes all logged-in users to risk, making this a significant concern for site administrators.
Affected Version(s)
Awesome Support β WordPress HelpDesk & Support Plugin 0 <= 6.4.0