CVE-2026-15932

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-01 07:16

Updated : 2026-08-26 16:31


NVD link : CVE-2026-15932

Mitre link : CVE-2026-15932

CVE.ORG link : CVE-2026-15932


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')