Insecure Direct Object References in Majestic Support Plugin by WordPress
CVE-2026-57646

5.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 June 2026

What is CVE-2026-57646?

The Majestic Support plugin for WordPress, specifically versions 1.1.7 and below, is prone to Insecure Direct Object References (IDOR). This vulnerability allows unauthorized users to access and manipulate sensitive data by directly referencing object identifiers. As a result, attackers can exploit specific endpoints to retrieve information that should be restricted, potentially compromising user privacy and security. It's crucial for users of the affected versions to apply appropriate updates and security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

Majestic Support <= 1.1.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

William Matos | Patchstack Bug Bounty Program
.