| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-4654 | Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 5.3 | 2026-04-08 07:43:03 | Deep Dive |
| CVE-2025-12641 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 6.5 | 2026-01-16 04:44:35 | Deep Dive |
| CVE-2025-58662 | WordPress Awesome Support plugin <= 6.3.5 - Deserialization of untrusted data vulnerability | awesomesupport | Awesome Support | High | 7.2 | 2025-09-22 18:23:01 | Deep Dive |
| CVE-2025-53340 | WordPress Awesome Support plugin <= 6.3.6 - Sensitive Data Exposure vulnerability | awesomesupport | Awesome Support | Medium | 5.3 | 2025-09-09 16:25:34 | Deep Dive |
| CVE-2025-31861 | WordPress Perfect Font Awesome Integration Plugin <= 2.3 - Stored Cross Site Scripting (XSS) vulnerability | WPOrbit Support | Perfect Font Awesome Integration | Medium | 6.5 | 2025-04-01 14:52:06 | Deep Dive |
| CVE-2024-13567 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | High | 7.5 | 2025-04-01 05:22:46 | Deep Dive |
| CVE-2024-54289 | WordPress Awesome Support plugin <= 6.3.1 - Broken Access Control vulnerability | awesomesupport | Awesome Support | Medium | 6.5 | 2024-12-13 14:25:05 | Deep Dive |
| CVE-2023-48324 | WordPress Awesome Support HelpDesk plugin <= 6.1.4 - Broken Access control vulnerability | awesomesupport | Awesome Support | 中危 | - | 2024-12-09 11:30:29 | Deep Dive |
| CVE-2023-49757 | WordPress Awesome Support plugin <= 6.1.10 - Broken Access Control + CSRF vulnerability | awesomesupport | Awesome Support | 中危 | - | 2024-12-09 11:30:13 | Deep Dive |
| CVE-2023-49857 | WordPress Awesome Support plugin <= 6.1.7 - Broken Access Control vulnerability | awesomesupport | Awesome Support | 中危 | - | 2024-12-09 11:30:01 | Deep Dive |
| CVE-2023-51537 | WordPress Awesome Support plugin <= 6.1.5 - Broken Access Control vulnerability | Awesome Support Team | Awesome Support | Medium | 5.3 | 2024-06-12 09:02:29 | Deep Dive |
| CVE-2024-35741 | WordPress Awesome Support plugin <= 6.1.7 - Broken Access Control vulnerability | Awesome Support Team | Awesome Support | Medium | 4.3 | 2024-06-10 07:41:55 | Deep Dive |
| CVE-2024-24716 | WordPress Awesome Support plugin <= 6.1.6 - Broken Access Control vulnerability | Awesome Support Team | Awesome Support | Medium | 5.4 | 2024-06-09 10:21:32 | Deep Dive |
| CVE-2024-30539 | WordPress Awesome Support plugin <= 6.1.7 - Broken Access Control vulnerability | Awesome Support Team | Awesome Support | Medium | 5.3 | 2024-06-09 09:04:27 | Deep Dive |
| CVE-2024-0596 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html() | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 5.3 | 2024-02-10 06:51:53 | Deep Dive |
| CVE-2024-0594 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | High | 8.8 | 2024-02-10 06:51:52 | Deep Dive |
| CVE-2024-0595 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via wpas_get_users() | awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 4.3 | 2024-02-10 06:51:52 | Deep Dive |
| CVE-2023-51538 | WordPress Awesome Support Plugin <= 6.1.5 is vulnerable to Cross Site Request Forgery (CSRF) | Awesome Support Team | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 4.3 | 2024-01-05 09:47:19 | Deep Dive |
| CVE-2023-48323 | WordPress Awesome Support Plugin <= 6.1.4 is vulnerable to Cross Site Request Forgery (CSRF) | Awesome Support Team | Awesome Support – WordPress HelpDesk & Support Plugin | Medium | 4.3 | 2023-11-30 12:59:15 | Deep Dive |
| CVE-2023-5355 | Awesome Support < 6.1.5 - Submitter+ Arbitrary File Deletion | Unknown | Awesome Support | 超危 | - | 2023-11-06 20:41:58 | Deep Dive |