CVE-2026-15932
Received Received - Intake

Directory Traversal in Support Genix WordPress Plugin

Vulnerability report for CVE-2026-15932, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension β€” including other users' private ticket attachments β€” from the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
support_genix support_genix to 1.4.48 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Support Genix WordPress plugin before version 1.4.48. It allows unauthenticated attackers to read arbitrary files on the server through a directory traversal flaw in the ticket-attachment download feature. Attackers can access files with allowlisted extensions, including other users' private ticket attachments.

Detection Guidance

Check if the Support Genix WordPress plugin version is below 1.4.48. Inspect server logs for unusual file access patterns or requests to the ticket-attachment download route with directory traversal sequences like '../'. Use tools like curl to test if arbitrary files can be accessed via the vulnerable endpoint.

Impact Analysis

This vulnerability can expose sensitive files on your server to attackers. They may access private ticket attachments, configuration files, or other sensitive data. This could lead to data breaches, loss of confidential information, or further compromise of your system.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA if it results in unauthorized access to personal or health data. GDPR requires protection of personal data, and HIPAA mandates safeguards for protected health information. A breach could result in legal penalties or fines.

Mitigation Strategies

Update the Support Genix WordPress plugin to version 1.4.48 or later immediately. If an update is not available, disable the plugin temporarily. Review server file permissions to restrict access to sensitive files. Monitor network traffic for suspicious activity targeting the plugin's endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15932. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart