Impact
The vulnerability in Awesome Support allows an authenticated user with subscriber or higher privileges to inject malicious scripts through the unescaped 'gdpr-data' parameter used in the wpas_gdpr_user_opt_out AJAX action. Because the plugin fails to verify the supplied gdpr-user ID and does not sanitize the input, attackers can store arbitrary JavaScript that executes in the browser of any user who views pages containing the injected payload. This attack can lead to session hijacking, defacement, or the execution of additional malicious payloads, compromising confidentiality and integrity of user sessions.
Affected Systems
Any WordPress installation running Awesome Support – WordPress HelpDesk & Support Plugin version 6.4.0 or earlier. The vulnerability exists universally across all affected releases, regardless of additional plugins or themes, due to the lack of input validation in the core plugin code.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access to the site with subscriber or higher privileges, and the attacker can trigger the injection via the exposed AJAX endpoint. While the impact does not provide remote code execution, the attack vector is local to authenticated users, making it exploitable in typical multi-user environments where subscribers exist.
OpenCVE Enrichment