CVE-2026-19946
Deferred Deferred - Pending Action

Missing Authorization in Awesome Support WordPress Plugin

Vulnerability report for CVE-2026-19946, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-11

Assigner: Wordfence

Description

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account β€” including administrators β€” permanently blocking their moderated activation and dispatching a denial notification email to the victim.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
awesome_support awesome_support to 6.3.9 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Awesome Support plugin for WordPress has a vulnerability in versions up to 6.3.9 due to missing authorization checks. The function wpas_do_mr_deny_user() does not verify user permissions like edit_users or edit_user before allowing changes. Instead, it relies on a nonce not scoped to the target user. This lets authenticated attackers with subscriber-level access or higher set a flag on any user account, including administrators, blocking their account permanently and sending a denial email.

Detection Guidance

Check WordPress installations for the Awesome Support plugin versions up to 6.3.9. Look for unauthorized user flagging by reviewing logs for wpas_do_mr_deny_user() function calls without proper capability checks. Inspect user accounts for unexpected mr_user_denied flags set on administrators or other users.

Impact Analysis

An attacker could exploit this to block your WordPress admin account permanently, preventing you from logging in. They could also send denial emails to you or other users, causing disruption. Since the attack requires only subscriber-level access, it is relatively easy to execute for authenticated users.

Compliance Impact

This vulnerability could lead to unauthorized access or denial of service, potentially violating GDPR's integrity principle or HIPAA's access controls. If user accounts are blocked, it may disrupt legitimate access, impacting compliance with availability requirements in these regulations.

Mitigation Strategies

Update the Awesome Support plugin to the latest version beyond 6.3.9. Remove subscriber-level access or higher for users who do not require it. Review user accounts for unauthorized mr_user_denied flags and remove them. Monitor for denial emails sent to administrators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19946. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart