Pricing
Case studies
Login
Start trial
Awesome Support
awesomesupport
Developer
6.3.7
Latest version
7,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
26 patched
12 Mitigation rules
WordPress Awesome Support - WordPress HelpDesk & Support Plugin plugin <= 6.1.7 - Missing Authorization via editor_html() vulnerability
<= 6.1.7
03/02/2026
WordPress Awesome Support - WordPress HelpDesk & Support Plugin plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion vulnerability
<= 6.3.6
16/01/2026
Deserialization of untrusted data vulnerability
<= 6.3.5
22/09/2025
Sensitive Data Exposure vulnerability
<= 6.3.6
14/08/2025
Unauthenticated Sensitive Information Exposure Through Unprotected Directory vulnerability
<= 6.3.1
31/03/2025
Broken Access Control vulnerability
<= 6.3.1
11/12/2024
Broken Access Control vulnerability
<= 6.1.7
06/06/2024
Broken Access Control vulnerability
<= 6.1.7
29/03/2024
Authenticated (Subscriber+) SQL Injection vulnerability
<= 6.1.7
12/02/2024
Broken Access Control vulnerability
<= 6.1.6
31/01/2024
Cross Site Request Forgery (CSRF) vulnerability
<= 6.1.5
27/12/2023
Broken Access Control vulnerability
<= 6.1.5
27/12/2023
Broken Access Control vulnerability
<= 6.1.7
07/12/2023
Broken Access Control + CSRF vulnerability
<= 6.1.10
04/12/2023
Broken Access control vulnerability
<= 6.1.4
23/11/2023
Cross Site Request Forgery (CSRF) vulnerability
<= 6.1.4
23/11/2023
Submitter+ Arbitrary File Deletion vulnerability
< 6.1.5
07/11/2023
Reflected Cross-Site Scripting vulnerability
< 6.1.5
07/11/2023
Insufficient permission check in wpas_edit_reply vulnerability
< 6.1.5
07/11/2023
Auth. Arbitrary Exported Tickets Download vulnerability
<= 6.1.1
07/11/2022
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities
<= 6.0.7
14/09/2022
Multiple Authenticated Reflected Cross-Site Scripting (XSS) vulnerabilities
<= 6.0.6
26/11/2021
Reflected Cross-Site Scripting (XSS) vulnerability
<= 6.0.8
09/08/2021
Stored Cross-Site Scripting (XSS) vulnerability
<= 5.8.2
06/01/2020
Authenticated Arbitrary File Deletion Vulnerability
<= 4.3.1
23/10/2017
Authenticated Arbitrary File Viewing Vulnerability
<= 4.3.1
23/10/2017