Vulnerabilities > Majesticsupport > Majestic Support > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-12 CVE-2024-13601 Authorization Bypass Through User-Controlled Key vulnerability in Majesticsupport Majestic Support
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via the 'exportusereraserequest' function due to missing validation on a user controlled key.
network
low complexity
majesticsupport CWE-639
4.3