CVE-2026-19946
Last modified
CVE-2026-19946 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account — including administrators — permanently blocking their moderated activation and dispatching a denial notification email to the victim.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| awesomesupport | Awesome Support – WordPress HelpDesk & Support Plugin | <= 6.3.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-19946?
How severe is CVE-2026-19946?
How do I fix CVE-2026-19946?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-1994The s2Member plugin for WordPress is vulnerable to privilege…9.8
- CVE-2026-19941An inapplicable NSEC record may be accepted by a `named` res…5.9
- CVE-2026-19942The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, …8.1
- CVE-2026-19943The Gutenverse – WordPress Blocks, Page Builder & Site Edito…6.4
- CVE-2026-19944The WP Crowdfunding plugin for WordPress is vulnerable to ge…4.9
- CVE-2026-19945The WP Crowdfunding plugin for WordPress is vulnerable to St…6.4
- CVE-2026-19948The Cozy Blocks – Page Builder for Gutenberg Editor & FSE wi…5.3
- CVE-2026-19949The All-in-One WP Migration and Backup plugin for WordPress …8.8
- CVE-2026-1995In versions before 7.0.0.64, IDrive’s id_service.exe process…7.8
- CVE-2026-19952The Frontend Admin by DynamiApps plugin for WordPress is vul…7.5
- CVE-2026-19953URI versions before 5.36 for Perl encode non-NFC host names …6.5
- CVE-2026-19955A vulnerability was detected in TrailDB 0.6. Impacted is the…3.5
Are you affected by CVE-2026-19946?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
