CVE-2026-57646
Deferred Deferred - Pending Action
Subscriber IDOR in Majestic Support <= 1.1.7

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Patchstack

Description
Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack majestic_support to 1.1.7 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

The vulnerability allows attackers to bypass authorization and authentication mechanisms, potentially accessing sensitive files, folders, or interacting with the database.

Such unauthorized access to sensitive data could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require strict controls to protect personal and sensitive information.

Therefore, if exploited, this vulnerability could negatively impact compliance with these common standards and regulations by exposing sensitive data.

Executive Summary

The WordPress Majestic Support Plugin, versions 1.1.7 and below, contains an Insecure Direct Object References (IDOR) vulnerability. This security flaw allows attackers to bypass authorization and authentication controls, potentially gaining unauthorized access to sensitive files, folders, or database interactions.

Although classified as low severity with a CVSS score of 5.4, this vulnerability poses a risk especially in large-scale exploit campaigns targeting many websites.

Impact Analysis

This vulnerability can allow attackers to bypass security mechanisms and access sensitive information or interact with the database without proper authorization.

  • Unauthorized access to sensitive files and folders.
  • Potential unauthorized database interactions.

While the severity is low, the risk increases in mass-exploit scenarios affecting many websites.

Mitigation Strategies

The vulnerability in the WordPress Majestic Support Plugin versions 1.1.7 and below can be mitigated by updating the plugin to version 1.1.8 or later.

If updating immediately is not possible, it is recommended to seek assistance from a hosting provider or a web developer.

Additionally, Patchstack users can enable auto-updates for vulnerable plugins to automatically mitigate this issue.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57646. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart