VYPR

Majestic Support

by WordPress

Source repositories

CVEs (10)

  • CVE-2025-48283CriMay 23, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Majestic Support Majestic Support majestic-support allows SQL Injection.This issue affects Majestic Support: from n/a through <= 1.1.0.

  • CVE-2025-26985HigFeb 25, 2025
    risk 0.53cvss 8.1epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.6.

  • CVE-2025-64284HigOct 29, 2025
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Majestic Support Majestic Support majestic-support allows PHP Local File Inclusion.This issue affects Majestic Support: from n/a through <= 1.0.7.

  • CVE-2024-13600HigFeb 12, 2025
    risk 0.42cvss 7.5epss 0.00

    The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the 'majesticsupportdata' directory. This makes it possible for unauthenticated…

  • CVE-2026-40778MedApr 15, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.2.

  • CVE-2025-49860MedSep 9, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support.This issue affects Majestic Support: from n/a through <= 1.1.0.

  • CVE-2025-48282MedMay 19, 2025
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Majestic Support Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through <= 1.1.0.

  • CVE-2024-13601MedFeb 12, 2025
    risk 0.21cvss 4.3epss 0.00

    The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user…

  • CVE-2026-13262MedJul 11, 2026
    risk 0.00cvss 6.5epss 0.00

    The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to generic SQL Injection via the 'val' parameter in all versions up to, and including, 1.1.9 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-57646MedJun 26, 2026
    risk 0.00cvss 5.4epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.