CVE-2024-0595: Awesome Support – WordPress HelpDesk & Support Plugin <= 6.1.7 - Missing Authorization via wpas_get_users()
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpasgetusers() function hooked via AJAX in all versions up to, and including, 6.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve user data such as emails. CVE-2024-35741 is likely a duplicate of this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0595?
CVE-2024-0595 is considered a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2024-0595?
To fix CVE-2024-0595, update the Awesome Support plugin to version 6.1.8 or later.
Who is affected by CVE-2024-0595?
CVE-2024-0595 affects all versions of the Awesome Support plugin for WordPress up to and including 6.1.7.
What type of vulnerability is CVE-2024-0595?
CVE-2024-0595 is an unauthorized access vulnerability arising from a missing capability check.
What can attackers do with CVE-2024-0595?
Attackers can exploit CVE-2024-0595 to gain unauthorized access to the user data through the wpas_get_users() function.