VYPR
Medium severity5.3NVD Advisory· Published Apr 15, 2026· Updated Apr 29, 2026

CVE-2026-40778

CVE-2026-40778

Description

Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Majestic Support WordPress plugin <=1.1.2 has a missing authorization vulnerability allowing unprivileged users to execute higher-privileged actions.

Vulnerability

Overview

CVE-2026-40778 is a missing authorization vulnerability in the Majestic Support WordPress plugin, affecting versions from n/a through 1.1.2. The plugin fails to properly enforce access controls, allowing users with lower privileges to perform actions meant for higher-privileged roles. This issue is classified as a broken access control vulnerability [1].

Exploitation

The vulnerability can be exploited without requiring authentication, as the missing checks occur in functions that should be restricted to authorized users. An attacker with any level of access, or potentially even unauthenticated, can trigger the vulnerable endpoints to gain elevated capabilities [1]. The CVSS score of 5.3 (Medium) reflects the moderate impact and low attack complexity.

Impact

Successful exploitation allows an attacker to perform actions that should be reserved for administrators, such as modifying plugin settings or accessing sensitive data. This could lead to partial site compromise, data exposure, or further exploitation [1].

Mitigation

The vendor has released version 1.1.3, which addresses the missing authorization. Users are strongly advised to update immediately. For those unable to update, implementing additional access controls or disabling the plugin temporarily is recommended [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1