← WordPress Vulnerabilities
WordPress security by component

Support Genix

Support Genix (support-genix-lite) is a WordPress plugin with 4 published CVE records in this archive. The latest tracked vulnerability was published Sep 01, 2026; the highest published CVSS base score is 9.9.

Plugin slug: support-genix-lite

CVE-2026-19806: Support Genix permits Subscriber-level administrator account takeover

Support Genix through 1.4.52 derives its site-wide AES-256-CBC key from three two-digit random values and an activation timestamp, leaving about 729,000 key candidates. A Subscriber who obtains one legitimate guest-ticket token and can bound the activation time can recover the key offline, forge a token for an administrator-owned ticket, and submit it through /sgnix/?p=. guest_ticket_login() then calls wp_set_auth_cookie() for that administrator without a capability, nonce, or session check.

PublishedSep 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for support-genix-lite
Safe version
Sep 01, 2026 CVE-2026-19806
Support Genix permits Subscriber-level administrator account takeover
Support Genix through 1.4.52 derives its site-wide AES-256-CBC key from three two-digit random values and an activation timestamp, leaving about 729,000 key candidates. A Subscriber who obtains one legitimate guest-ticket token and can bound the activation time can recover the key offline, forge a token for an administrator-owned ticket, and submit it through /sgnix/?p=. guest_ticket_login() then calls wp_set_auth_cookie() for that administrator without a capability, nonce, or session check.
See mitigation notes
CVE8.8
NVDPending
Sep 03, 2025 CVE-2025-58635
Support Genix: A security weakness
Support Genix is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Mar 27, 2025 CVE-2025-30777
Support Genix: A security weakness
Support Genix is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Apr 18, 2024 CVE-2023-49742
Support Genix: A security weakness
Support Genix is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.9
NVDPending