The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 01 Oct 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getawesomesupport
Getawesomesupport awesome Support Wordpress-extensions Wordpress-extensions awesome Support |
|
| Vendors & Products |
Getawesomesupport
Getawesomesupport awesome Support Wordpress-extensions Wordpress-extensions awesome Support |
Thu, 01 Oct 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr-data' parameter in all versions up to, and including, 6.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users against other accounts because the AJAX handlers accept an arbitrary gdpr-user ID without verifying it belongs to the requester, and the required wpas-gdpr-nonce is emitted via wp_localize_script to every logged-in user on frontend plugin pages and on /wp-admin/profile.php. | |
| Title | Awesome Support <= 6.4.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'gdpr-data' Parameter via wpas_gdpr_user_opt_out AJAX Action | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-01T18:20:21.281Z
Reserved: 2026-09-22T20:26:44.298Z
Link: CVE-2026-96268
No data.
Status : Deferred
Published: 2026-10-01T09:17:10.433
Modified: 2026-10-01T12:40:28.083
Link: CVE-2026-96268
No data.
OpenCVE Enrichment
Updated: 2026-10-01T15:35:57Z
Weaknesses