Majestic Support <= 1.1.9 - Authenticated (Subscriber+) SQL Injection via 'val' Parameter
medium
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL q...
- CVSS:
- 6.5
- Affected:
- up to 1.1.9
- Fixed in:
- 1.2.0
- Disclosed:
- Jul 10, 2026
CVE-2026-13262 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.1.7 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.7 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level acc...
- CVSS:
- 4.3
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.8
- Disclosed:
- Jun 26, 2026
CVE-2026-57646 on NVD →
Majestic Support <= 1.1.2 - Missing Authorization
medium
The Majestic Support plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.1.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.3
- Disclosed:
- Apr 9, 2026
CVE-2026-40778 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] <= 1.1.1 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.1.1.
- Affected:
- up to 1.1.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 29, 2025
CVE-2025-64284 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.1.1
unknown
[en] Missing Authorization vulnerability in Majestic Support Majestic Support. This issue affects Majestic Support: from n/a through 1.1.0.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- Sep 9, 2025
CVE-2025-49860 on NVD →
Majestic Support <= 1.1.0 - Missing Authorization
medium
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- Jun 12, 2025
CVE-2025-49860 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.1.1
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support allows SQL Injection. This issue affects Majestic Support: from n/a through 1.1.0.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- May 23, 2025
CVE-2025-48283 on NVD →
Majestic Support <= 1.1.0 - Unauthenticated SQL Injection
high
The Majestic Support plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.1.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL querie...
- CVSS:
- 7.5
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- May 22, 2025
CVE-2025-48283 on NVD →
Majestic Support <= 1.1.0 - Missing Authorization
medium
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.1.0
- Fixed in:
- 1.1.1
- Disclosed:
- May 19, 2025
CVE-2025-48282 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.1.1
unknown
[en] Missing Authorization vulnerability in Majestic Support Majestic Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Majestic Support: from n/a through 1.1.0.
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.1
- Disclosed:
- May 19, 2025
CVE-2025-48282 on NVD →
Majestic Support <= 1.0.7 - Authenticated (Contributor+) Local File Inclusion
high
The Majestic Support plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those file...
- CVSS:
- 7.5
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.8
- Disclosed:
- Apr 22, 2025
CVE-2025-64284 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.0.7
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support allows PHP Local File Inclusion. This issue affects Majestic Support: from n/a through 1.0.6.
- Affected:
- up to 1.0.7
- Fixed in:
- 1.0.7
- Disclosed:
- Feb 25, 2025
CVE-2025-26985 on NVD →
Majestic Support <= 1.0.6 - Unauthenticated Local File Inclusion
critical
The Majestic Support plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access con...
- CVSS:
- 9.8
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.7
- Disclosed:
- Feb 23, 2025
CVE-2025-26985 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.0.6
unknown
[en] The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Feb 12, 2025
CVE-2024-13600 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin [majestic-support] < 1.0.6
unknown
[en] The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it possible for aut...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Feb 12, 2025
CVE-2024-13601 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Unauthenticated Sensitive Information Exposure Through Unprotected Directory
high
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored inse...
- CVSS:
- 7.5
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Feb 11, 2025
CVE-2024-13600 on NVD →
Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin <= 1.0.5 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key. This makes it possible for authenti...
- CVSS:
- 4.3
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.6
- Disclosed:
- Feb 11, 2025
CVE-2024-13601 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database