Sceawere
Vulnerability Detail
CVE-2026-96820UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Awesome Support Subscriber XSS Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- awesomesupport
- Product
- Awesome Support
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Cross Site Scripting (XSS) in Awesome Support <= 6.3.9 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:31.440Z",
"pubdate": "2026-09-30T13:17:31.440Z",
"executiveSummary": "Awesome Support versions 6.3.9 and below are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis flaw allows authenticated users with subscriber-level privileges to inject malicious JavaScript into the application.\nThe vulnerability occurs due to improper sanitization of user-supplied input before rendering it in the browser.\nIf successfully exploited, an attacker can execute arbitrary scripts within the context of an administrator's session.\nPotential impacts include unauthorized actions on behalf of the administrator, session hijacking, credential theft, or site defacement.\nThe attack is performed via the web interface and requires low-privilege account access to initiate.\nRemediation involves updating the plugin to a patched version once available and ensuring strict input validation protocols are applied to all user-facing fields.",
"technicalDetails": "The vulnerability resides in the Awesome Support plugin, specifically affecting versions 6.3.9 and earlier. The root cause is the failure to adequately sanitize or escape user-supplied data during the input process, which is subsequently rendered in an administrative context.\nAttackers with subscriber-level access can supply a malicious payload within fields processed by the plugin. Because the application fails to perform output encoding, the browser interprets the injected script as legitimate code rather than harmless text.\nThe attack flow begins when an authenticated subscriber submits a crafted request containing an XSS payload, such as a script tag or an event handler (e.g., onerror, onload) inside an input field. Once stored, this payload remains persistent within the application database.\nThe exploit triggers when an administrator views the affected ticket, post, or administrative dashboard interface where the malicious data is displayed. The script executes within the administrator's browser session, granting the attacker the same permissions as the victim.\nDue to the nature of stored XSS, the payload executes automatically without user interaction other than viewing the compromised page. This enables the attacker to manipulate the Document Object Model (DOM), intercept sensitive session tokens, perform unauthorized administrative operations, or redirect the user to malicious external sites.\nThe vulnerability is accessible over the network via standard HTTP/HTTPS protocols. Since the exploit relies on the processing logic of the plugin's backend handling of user-submitted content, it bypasses basic client-side security measures. The impact is significant as it facilitates lateral movement within the WordPress environment, effectively escalating the subscriber's influence to that of the logged-in administrator."
}