PT-2026-3211 · WordPress · Wordpress+1
Angus Girvan
·
Published
2026-01-16
·
Updated
2026-01-16
·
CVE-2025-12641
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Awesome Support - WordPress HelpDesk & Support Plugin versions prior to 6.3.7
Description
The Awesome Support plugin for WordPress is affected by an authorization bypass. This is due to insufficient capability checks within the
wpas do mr activate user function, which does not properly verify user permissions when modifying roles. A nonce reuse issue exists where nonces intended for public registration are also valid for privileged actions because all actions share the same nonce namespace. An unauthenticated attacker can exploit this by submitting a request to the 'wpas-do=mr activate user' action with a user-controlled user id parameter, provided they have access to a valid nonce from the public registration or submit ticket page. This allows them to demote administrators to lower-privilege roles.Recommendations
Update to version 6.3.7 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Awesome Support
Wordpress