The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
History

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
Title Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-01T06:00:07.998Z

Reserved: 2026-07-16T07:53:32.791Z

Link: CVE-2026-15932

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.