Description
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php.
Published: 2026-10-01
Score: 6.4 Medium
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Awesome Support allows an authenticated user with subscriber or higher privileges to inject malicious scripts through the unescaped 'gdpr-data' parameter used in the wpas_gdpr_user_opt_out AJAX action. Because the plugin fails to verify the supplied gdpr-user ID and does not sanitize the input, attackers can store arbitrary JavaScript that executes in the browser of any user who views pages containing the injected payload. This attack can lead to session hijacking, defacement, or the execution of additional malicious payloads, compromising confidentiality and integrity of user sessions.

Affected Systems

Any WordPress installation running Awesome Support – WordPress HelpDesk & Support Plugin version 6.4.0 or earlier. The vulnerability exists universally across all affected releases, regardless of additional plugins or themes, due to the lack of input validation in the core plugin code.

Risk and Exploitability

The CVSS score of 6.4 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access to the site with subscriber or higher privileges, and the attacker can trigger the injection via the exposed AJAX endpoint. While the impact does not provide remote code execution, the attack vector is local to authenticated users, making it exploitable in typical multi-user environments where subscribers exist.

Generated by OpenCVE AI on October 1, 2026 at 11:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Awesome Support to a version higher than 6.4.0 where the gdpr-data input is properly sanitized and escaped.
  • If an upgrade cannot be performed immediately, disable the GDPR data endpoint by removing the wpas_gdpr_user_opt_out AJAX action, for example by adding a custom snippet that calls remove_action("wp_ajax_wpas_gdpr_user_opt_out", "wpas_gdpr_user_opt_out_handler").
  • Implement a site‑wide Content Security Policy that restricts script sources to trusted domains to mitigate the effects of any remaining XSS payloads.

Generated by OpenCVE AI on October 1, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Getawesomesupport
Getawesomesupport awesome Support
Wordpress-extensions
Wordpress-extensions awesome Support
Vendors & Products Getawesomesupport
Getawesomesupport awesome Support
Wordpress-extensions
Wordpress-extensions awesome Support

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php.
Title Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Getawesomesupport Awesome Support
Wordpress-extensions Awesome Support
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T18:20:21.281Z

Reserved: 2026-09-22T20:26:44.298Z

Link: CVE-2026-96268

cve-icon Vulnrichment

Updated: 2026-10-01T18:20:18.458Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:10.433

Modified: 2026-10-01T19:17:25.807

Link: CVE-2026-96268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:35:57Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')