CyberRota Analysis
AI-GeneratedThe Support Genix WordPress plugin prior to version 1.4.48 is vulnerable due to improper access controls, enabling unauthenticated users to download private ticket attachments by exploiting known file names. This could lead to unauthorized access to sensitive information shared within support tickets. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data exposure risks.
Original NVD Description
The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.