← WordPress Vulnerabilities
WordPress security by component

Support Genix

Support Genix is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 3.7.

Plugin slug: support-genix

CVE-2026-15932: Support Genix attachment downloads let visitors traverse and read server files

Support Genix before 1.4.48 does not prevent directory traversal in its ticket-attachment download route. An unauthenticated visitor can supply a crafted path that escapes the intended attachment directory and read server files whose extension is on the route's allowlist, including private attachments from other users' tickets. The published record does not disclose the route, path parameter, traversal encoding or download function.

PublishedAug 01, 2026
Known safe version1.4.48
Safe version
Aug 01, 2026 CVE-2026-15932
Support Genix attachment downloads let visitors traverse and read server files
Support Genix before 1.4.48 does not prevent directory traversal in its ticket-attachment download route. An unauthenticated visitor can supply a crafted path that escapes the intended attachment directory and read server files whose extension is on the route's allowlist, including private attachments from other users' tickets. The published record does not disclose the route, path parameter, traversal encoding or download function.
1.4.48
CVEPending
NVDPending
Jul 31, 2026 CVE-2026-14862
Support Genix attachment names can unlock private ticket files
Support Genix before 1.4.48 does not adequately authorize support-ticket attachment downloads. An unauthenticated visitor who obtains a stored attachment filename can request and download another user's private ticket attachment. The published record does not identify how a filename is obtained, the download route or parameter, or the file-serving callback, so filename disclosure remains a separate prerequisite and the exact request mechanics are unknown.
1.4.48
CVE3.7
NVDPending