Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter
Awesome Support – WordPress HelpDesk & Support Plugin
Minimum safe version
6.3.8
Update to 6.3.8 or later to address 31 fixable vulnerabilities
CVE-2025-12641
Awesome Support <= 6.3.5 - Authenticated (Support Manager+) PHP Object Injection
CVE-2025-53340
CVE-2024-13567
CVE-2024-54289
CVE-2024-35741
CVE-2024-30539
CVE-2024-0594
CVE-2024-0595
CVE-2024-0596
CVE-2024-24716
WordPress Awesome Support Plugin <= 6.1.5 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress Awesome Support Plugin <= 6.1.5 is vulnerable to Broken Access Control
CVE-2023-49857
CVE-2023-49757
CVE-2023-48324
CVE-2023-48323
WordPress Awesome Support Plugin < 6.1.5 is vulnerable to Arbitrary File Deletion
WordPress Awesome Support Plugin < 6.1.5 is vulnerable to Broken Access Control
WordPress Awesome Support Plugin < 6.1.5 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-3511
CVE-2022-38073
WordPress Awesome Support plugin <= 4.3.1 - Authenticated Arbitrary File Viewing Vulnerability
WordPress Awesome Support plugin <= 4.3.1 - Authenticated Arbitrary File Deletion Vulnerability
WordPress Awesome Support plugin <= 6.0.8 - Reflected Cross-Site Scripting (XSS) vulnerability
CVE-2015-9318
CVE-2015-9317
CVE-2019-20181
CVE-2021-24435
CVE-2021-36919