Description
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account — including administrators — permanently blocking their moderated activation and dispatching a denial notification email to the victim.
Published: 2026-09-09
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Account Denial
Action: Apply Patch
AI Analysis

Impact

The Awesome Support plugin for WordPress contains a missing authorization check in versions up to 6.3.9. The flaw resides in the wpas_do_mr_deny_user() function, which fails to enforce current_user_can('edit_users') or current_user_can('edit_user') checks. As a result, any authenticated user with subscriber-level access or higher can set the mr_user_denied flag on any user account, including administrators. This permanently blocks the user’s moderated activation and triggers a denial notification email, effectively denying service to the targeted account.

Affected Systems

The vulnerability affects installations of the Awesome Support – WordPress HelpDesk & Support Plugin version 6.3.9 and all earlier releases. No narrower version subset was specified, meaning any deployment of this plugin at or before 6.3.9 is impacted.

Risk and Exploitability

The CVSS score of 4.3 indicates a moderate severity and the EPSS score is not available, so actual exploitation probability is unclear. The flaw is listed as not in KEV and relies on a simple missing capability check, implying that exploitation requires only authenticated access and the ability to construct a request with a user identifier. The likely attack vector therefore is an authenticated, web‑based request where the attacker supplies a user_id of an account they wish to deny. Because the nonce is not scoped to the target user, the check does not prevent such misuse, enabling a subscriber or higher role to deny any user.

Generated by OpenCVE AI on September 9, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Awesome Support plugin version 6.4.0 or newer, where the missing authorization check has been added.
  • Remove or revoke the edit_users capability from Subscriber and any role lower than Administrator to prevent unintended use of the denial function.
  • Implement a custom filter or role check that blocks execution of wpas_do_mr_deny_user() for users lacking edit_users capability if an immediate plugin upgrade cannot be performed.

Generated by OpenCVE AI on September 9, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Awesomesupport
Awesomesupport awesome Support Wordpress Helpdesk & Support
Wordpress
Wordpress wordpress
Vendors & Products Awesomesupport
Awesomesupport awesome Support Wordpress Helpdesk & Support
Wordpress
Wordpress wordpress

Wed, 09 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account — including administrators — permanently blocking their moderated activation and dispatching a denial notification email to the victim.
Title Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Awesomesupport Awesome Support Wordpress Helpdesk & Support
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:14.539Z

Reserved: 2026-08-15T16:51:37.070Z

Link: CVE-2026-19946

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-09T06:17:15.660

Modified: 2026-09-11T21:17:09.027

Link: CVE-2026-19946

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:09Z

Weaknesses