SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14862

LOW · CVSS 3.7 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The Support Genix WordPress plugin prior to version 1.4.48 is vulnerable due to improper access controls, enabling unauthenticated users to download private ticket attachments by exploiting known file names. This could lead to unauthorized access to sensitive information shared within support tickets. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.

CVE
CVE-2026-14862
Severity
LOW
CVSS
3.7
EPSS
0.17%
WordPress

Original NVD Description

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.