PT-2025-6444 · WordPress · The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin

Tim Coen

·

Published

2025-02-12

·

Updated

2025-02-12

·

CVE-2024-13600

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress versions up to, and including, 1.0.5
Description The issue allows unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads/majesticsupportdata directory, which can contain file attachments included in support tickets. This is possible due to sensitive information exposure in the majesticsupportdata directory.
Recommendations For versions up to, and including, 1.0.5, consider restricting access to the /wp-content/uploads/majesticsupportdata directory to minimize the risk of exploitation. As a temporary workaround, restrict access to the majesticsupportdata directory until a patch is available.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-13600

Affected Products

The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin