CVE-2026-102382: WordPress Majestic Support plugin <= 1.2.0 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 1, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in Ahmad Majestic Support majestic-support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Majestic Support: from n/a through 1.2.0.
Affected Software
1 affected component
Ahmad Majestic Support Majestic Support<=1.2.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Majestic Supportto a version that resolves this vulnerability.Fixed in 1.2.1
Event History
Oct 1, 2026
CVE Published
via MITRE·12:31 PM
Data Sourced
via MITRE·12:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vector requires network access and low privileges. No user interaction is required.
2
What security impact is indicated?
The issue is rated medium with a CVSS score of 4.3. It can affect integrity, while confidentiality and availability impact are listed as none.
3
Which versions are affected?
Majestic Support versions through 1.2.0 are affected. The available data does not identify a fixed version.