CVE-2026-14862

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-14862

Mitre link : CVE-2026-14862

CVE.ORG link : CVE-2026-14862


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization