Junglewise Threat Intelligence

CVE-2026-13262: ahmadmj Majestic Support SQL injection in val parameter

CVE-2026-13262 · Severity: medium · CVSS 6.5 · Published 2026-07-11

Executive brief

Majestic Support, a customer service and help desk plugin for WordPress, contains a security flaw that could allow logged-in users to access sensitive information from the website's database. By exploiting this vulnerability, an attacker with basic account access (such as a subscriber) could potentially steal private data, including user details or configuration settings. This could lead to a significant breach of customer privacy and organizational data.

Technical details

A generic SQL injection vulnerability exists in the Majestic Support plugin for WordPress due to insufficient escaping of the 'val' parameter and a lack of prepared statements in the underlying SQL query. While the vulnerability is technically unauthenticated in its root cause, practical exploitation requires a valid 'get-smart-reply' nonce. This nonce can be obtained by any Subscriber-level user by creating a ticket and viewing the ticket detail page, effectively making this an authenticated vulnerability (PR:L). Attackers can append malicious SQL queries to existing ones to exfiltrate sensitive data from the WordPress database. The issue is addressed in version 1.2.0.

Affected products

  • ahmadmj Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin up to, and including, 1.1.9

Timeline

  • 2026-07-11: advisory: NVD publication date
  • 2026-07-11: disclosed: Wordfence disclosure date

References