# CVE-2026-19946

## Summary

- **CVE ID:** CVE-2026-19946
- **Severity:** MEDIUM
- **CVSS Score:** 4.3 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
- **CWE:** CWE-862
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_do_mr_activate_user() does not enforce current_user_can('edit_users') or current_user_can('edit_user', $user_id), relying solely on a nonce that is not scoped to the target user. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the mr_user_denied flag on any user account — including administrators — permanently blocking their moderated activation and dispatching a denial notification email to the victim.

## Affected Products

- awesomesupport — Awesome Support – WordPress HelpDesk & Support Plugin (0)

## References

- [CNA](https://www.wordfence.com/threat-intel/vulnerabilities/id/208f9475-446c-4cf1-9d70-a845cf9b3005?source=cve)
- [CNA](https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.3.9/includes/functions-user.php#L1731)
- [CNA](https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.3.9/includes/functions-actions.php#L25)
- [CNA](https://plugins.trac.wordpress.org/browser/awesome-support/tags/6.3.9/includes/functions-user.php#L1650)
- [CNA](https://plugins.trac.wordpress.org/log/awesome-support/)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._