Impact
Missing authorization in the Majestic Support plugin allows an attacker to perform operations normally restricted to authorized users. The vulnerability enables reading or modifying data handled by the plugin, potentially exposing sensitive information or altering help requests. The weakness is documented as CWE‑862, reflecting an improper authorization control.
Affected Systems
The flaw affects installations of the Majestic Support WordPress plugin version 1.1.0 or earlier. Any WordPress site that has this plugin installed and enabled is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be a web‑based request to the plugin’s backend since it is a WordPress plugin. Exploitation requires the attacker to send crafted HTTP requests to the plugin’s endpoints, gaining unauthorized access to its features. The overall risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
EUVD