Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
getawesomesupport vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2023-5352
The Awesome Support WordPress plugin prior to 6.1.5 does not correctly authorize the wpas_edit_reply function, allowing users to edit posts for which they do not have permission.
Getawesomesupport Awesome Support
6.1
CVSSv3
CVE-2023-5354
The Awesome Support WordPress plugin prior to 6.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
Getawesomesupport Awesome Support
8.1
CVSSv3
CVE-2023-5355
The Awesome Support WordPress plugin prior to 6.1.5 does not sanitize file paths when deleting temporary attachment files, allowing a ticket submitter to delete arbitrary files on the server.
Getawesomesupport Awesome Support
4.8
CVSSv3
CVE-2019-20181
The awesome-support plugin 5.8.0 for WordPress allows XSS via the post_title parameter.
Getawesomesupport Awesome Support
5.4
CVSSv3
CVE-2022-38073
Multiple Authenticated (custom specific plugin role) Persistent Cross-Site Scripting (XSS) vulnerability in Awesome Support plugin <= 6.0.7 at WordPress.
Getawesomesupport Awesome Support
6.1
CVSSv3
CVE-2015-9317
The awesome-support plugin prior to 3.1.7 for WordPress has XSS via custom information messages.
Getawesomesupport Awesome Support
7.5
CVSSv3
CVE-2015-9318
The awesome-support plugin prior to 3.1.7 for WordPress has a security issue in which shortcodes are allowed in replies.
Getawesomesupport Awesome Support
8.8
CVSSv3
CVE-2024-0594
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to union-based SQL Injection via the 'q' parameter of the wpas_get_users action in all versions up to, and including, 6.1.7 due to insufficient escaping on the user su...
Getawesomesupport Awesome Support
4.3
CVSSv3
CVE-2024-0595
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpas_get_users() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for...
Getawesomesupport Awesome Support
5.3
CVSSv3
CVE-2024-0596
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the editor_html() function in all versions up to, and including, 6.1.7. This makes it possible for authentica...
Getawesomesupport Awesome Support
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »