Missing Authorization
13 records48.1%First: 2022. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 27 vulnerability records associated with Awesome Support – WordPress HelpDesk & Support Plugin, published between 2015 and 2026.
Dataset last synchronized: 2026-08-03 00:31:25 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2015 | 2 | |
| 2020 | 1 | |
| 2021 | 2 | |
| 2022 | 2 | |
| 2023 | 9 | |
| 2024 | 6 | |
| 2025 | 3 | |
| 2026 | 2 |
| Severity | Records | Share |
|---|---|---|
| High | 5 | 18.5% |
| Medium | 22 | 81.5% |
First: 2022. Latest: 2026.
First: 2015. Latest: 2023.
First: 2015. Latest: 2025.
First: 2023. Latest: 2023.
First: 2025. Latest: 2025.
First: 2023. Latest: 2023.
First: 2024. Latest: 2024.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
6.3.86.3.66.3.76.3.26.1.76.1.66.1.86.1.116.1.56.1.26.0.86.0.76.0.116.0.143.1.7Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-6.3.7 | Awesome Support <= 6.3.7 - Authenticated (Subscriber+) Insecure Direct Object Reference to Unauthorized Ticket Reply Access via 'ticket_id' Parameter | April 7, 2026 | 6.3.8 | Medium |
*-6.3.6 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.6 - Missing Authorization to Unauthenticated Role Demotion | January 15, 2026 | 6.3.7 | Medium |
*-6.3.5 | Awesome Support <= 6.3.5 - Authenticated (Support Manager+) PHP Object Injection | September 22, 2025 | 6.3.6 | High |
*-6.3.6 | Awesome Support <= 6.3.6 - Information Exposure | August 14, 2025 | 6.3.7 | Medium |
*-6.3.1 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.3.1 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory | March 31, 2025 | 6.3.2 | High |
*-6.3.1 | Awesome Support <= 6.3.1 - Missing Authorization | December 11, 2024 | 6.3.2 | Medium |
*-6.1.7 | Awesome Support <= 6.1.7 - Missing Authorization | March 29, 2024 | 6.1.8 | Medium |
*-6.1.6 | Awesome Support <= 6.1.6 - Insufficient Authorization via wpas_can_delete_attachments() | March 12, 2024 | 6.1.7 | Medium |
*-6.1.7 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via editor_html() | February 9, 2024 | 6.1.8 | Medium |
*-6.1.7 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via wpas_get_users() | February 9, 2024 | 6.1.8 | Medium |
*-6.1.7 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Authenticated (Subscriber+) SQL Injection | February 9, 2024 | 6.1.8 | High |
*-6.1.5 | Awesome Support <= 6.1.5 - Cross-Site Request Forgery | December 27, 2023 | 6.1.6 | Medium |
*-6.1.5 | Awesome Support <= 6.1.5 - Missing Authorization via wpas_load_reply_history | December 27, 2023 | 6.1.6 | Medium |
*-6.1.7 | Awesome Support <= 6.1.7 - Missing Authorization | December 7, 2023 | 6.1.8 | Medium |
*-6.1.10 | Awesome Support <= 6.1.10 - Missing Authorization | December 4, 2023 | 6.1.11 | Medium |
*-6.1.4 | Awesome Support <= 6.1.4 - Cross-Site Request Forgery via wpas_edit_reply_ajax() | November 23, 2023 | 6.1.5 | Medium |
*-6.1.4 | Awesome Support <= 6.1.4 - Missing Authorization via wpas_edit_reply_ajax() | November 23, 2023 | 6.1.5 | Medium |
*-6.1.4 | Awesome Support <= 6.1.4 - Authenticated (Submitter+) Arbitrary File Deletion | October 16, 2023 | 6.1.5 | High |
*-6.1.4 | Awesome Support <= 6.1.4 - Reflected Cross-Site Scripting | October 16, 2023 | 6.1.5 | Medium |
*-6.1.4 | Awesome Support <= 6.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Modification | October 16, 2023 | 6.1.5 | Medium |
*-6.1.1 | Awesome Support <= 6.1.1 - Insecure Direct Object Reference to (Subscriber+) Ticket Export | November 7, 2022 | 6.1.2 | Medium |
*-6.0.7 | Awesome Support <= 6.0.7 - Authenticated Stored Cross-Site Scripting | September 14, 2022 | 6.0.8 | High |
*-6.0.6 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.6 - Reflected Cross-Site Scripting | November 26, 2021 | 6.0.7 | Medium |
*-6.0.10 | Titan Framework <= (Various Versions) - Reflected Cross-Site Scripting | August 9, 2021 | 6.0.11 | Medium |
*-6.0.13 | Awesome Support – WordPress HelpDesk & Support Plugin <= 6.0.13 - Cross-Site Scripting via post_title | January 6, 2020 | 6.0.14 | Medium |
Selected source records
Published: April 7, 2026
Published: January 15, 2026
Published: September 22, 2025
Published: August 14, 2025
Published: March 31, 2025
Published: December 11, 2024
Published: March 29, 2024
Published: March 12, 2024
Published: February 9, 2024
Published: October 16, 2023
Published: March 31, 2025
Published: September 22, 2025
Published: September 14, 2022
Published: January 15, 2026
Published: May 15, 2015
Published: May 15, 2015
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.