WordPress security by component
Support Genix
Plugin description
Support Genix is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 01, 2026; the highest published CVSS base score is 3.7.
Plugin slug:
support-genixLatest vulnerability
CVE-2026-15932: Support Genix attachment downloads let visitors traverse and read server files
Support Genix before 1.4.48 does not prevent directory traversal in its ticket-attachment download route. An unauthenticated visitor can supply a crafted path that escapes the intended attachment directory and read server files whose extension is on the route's allowlist, including private attachments from other users' tickets. The published record does not disclose the route, path parameter, traversal encoding or download function.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-15932
Support Genix attachment downloads let visitors traverse and read server files
Support Genix before 1.4.48 does not prevent directory traversal in its ticket-attachment download route. An unauthenticated visitor can supply a crafted path that escapes the intended attachment directory and read server files whose extension is on the route's allowlist, including private attachments from other users' tickets. The published record does not disclose the route, path parameter, traversal encoding or download function.
|
1.4.48 |
CVEPending
NVDPending
|
| Jul 31, 2026 |
CVE-2026-14862
Support Genix attachment names can unlock private ticket files
Support Genix before 1.4.48 does not adequately authorize support-ticket attachment downloads. An unauthenticated visitor who obtains a stored attachment filename can request and download another user's private ticket attachment. The published record does not identify how a filename is obtained, the download route or parameter, or the file-serving callback, so filename disclosure remains a separate prerequisite and the exact request mechanics are unknown.
|
1.4.48 |
CVE3.7
NVDPending
|