Impact
The Awesome Support plugin for WordPress contains a missing authorization check in versions up to 6.3.9. The flaw resides in the wpas_do_mr_deny_user() function, which fails to enforce current_user_can('edit_users') or current_user_can('edit_user') checks. As a result, any authenticated user with subscriber-level access or higher can set the mr_user_denied flag on any user account, including administrators. This permanently blocks the user’s moderated activation and triggers a denial notification email, effectively denying service to the targeted account.
Affected Systems
The vulnerability affects installations of the Awesome Support – WordPress HelpDesk & Support Plugin version 6.3.9 and all earlier releases. No narrower version subset was specified, meaning any deployment of this plugin at or before 6.3.9 is impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity and the EPSS score is not available, so actual exploitation probability is unclear. The flaw is listed as not in KEV and relies on a simple missing capability check, implying that exploitation requires only authenticated access and the ability to construct a request with a user identifier. The likely attack vector therefore is an authenticated, web‑based request where the attacker supplies a user_id of an account they wish to deny. Because the nonce is not scoped to the target user, the check does not prevent such misuse, enabling a subscriber or higher role to deny any user.
OpenCVE Enrichment