CVE-2026-14862
Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.
| Vendor | unknown |
| Product | support genix |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown support genix
Be the first to know when new unknown vulnerabilities affecting unknown support genix are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Support Genix
0 < 1.4.48
References
Credits
Alessandro Greco aka Aleff Giovanbattista Ianni (University of Calabria - UNICAL) WPScan