CVE-2026-14862
Received Received - Intake

Unauthenticated File Download in Support Genix WordPress Plugin

Vulnerability report for CVE-2026-14862, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-31

Last updated on: 2026-07-31

Assigner: WPScan

Description

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-31
Last Modified
2026-07-31
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
support_genix support_genix to 1.4.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Support Genix WordPress plugin before version 1.4.48 has a flaw where it does not properly restrict access to support ticket attachments. Unauthenticated users can download private ticket attachments if they know the stored filename, which follows a predictable pattern. The exploit requires the exact filename, as using the original name alone does not work.

Detection Guidance

Check for outdated Support Genix plugin versions below 1.4.48 by inspecting WordPress installations. Look for predictable attachment paths like wp-content/uploads/support-genix/{ticket_id}/attached_files/{md5}___{original-name} in server logs or file structures.

Impact Analysis

This vulnerability allows unauthorized users to access private ticket attachments, potentially exposing sensitive information. However, exploitation is limited because attackers need the exact stored filename, which may require obtaining it through other means like leaked links.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA due to unauthorized access to private ticket attachments. GDPR requires protection of personal data, and HIPAA mandates safeguarding protected health information. Unauthorized access to attachments containing such data could violate these regulations.

Mitigation Strategies

Update the Support Genix plugin to version 1.4.48 or later immediately. Review server logs for suspicious attachment download attempts and restrict access to sensitive ticket files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14862. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart