Junglewise Threat Intelligence

CVE-2026-57646: Majestic Support IDOR in WordPress plugin

CVE-2026-57646 · Severity: medium · CVSS 5.4 · Published 2026-06-26

Executive brief

Majestic Support is a WordPress plugin used to manage customer support tickets and interactions. A security flaw in versions 1.1.7 and earlier allows logged-in users with low-level 'Subscriber' permissions to access or modify data they should not be able to see, potentially leading to the exposure of sensitive support information or unauthorized changes to records.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in the Majestic Support plugin for WordPress (versions <= 1.1.7) due to insufficient authorization checks on user-controlled keys (CWE-639). An attacker authenticated with Subscriber-level privileges can exploit this by manipulating identifiers in requests to the server. This allows the attacker to bypass intended access controls to view sensitive files, folders, or interact with database records belonging to other users. The issue is resolved in version 1.1.8.

Affected products

  • Majestic Support Majestic Support <= 1.1.7

Timeline

  • 2026-06-01: disclosed: Reported by William Matos
  • 2026-06-26: advisory: Published by Patchstack and NVD
  • 2026-06-26: patched: Patch released in version 1.1.8

References