What is CVE-2026-14862?
The Support Genix WordPress plugin before version 1.4.48 fails to properly authorize access to support-ticket attachment downloads, allowing unauthenticated users to download other users' private ticket attachments if they obtain the stored file name. Updating to version 1.4.48 or later is recommended.
Azərbaycanca: Support Genix WordPress plaqininin 1.4.48-dən əvvəlki versiyaları dəstək biletlərinə əlavə edilmiş faylların yüklənməsi üçün avtorizasiya yoxlamasını düzgün həyata keçirmir. Bu zəiflik autentifikasiya olunmamış şəxslərə saxlanılmış fayl adını əldə etməklə digər istifadəçilərin məxfi bilet əlavələrini yükləməyə imkan yaradır. Plaqini ən azı 1.4.48 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What is the CVE-2026-14862 vulnerability in the Support Genix WordPress plugin?
This vulnerability exists in versions of the plugin before 1.4.48, where it fails to properly authorize access to support-ticket attachment downloads. This allows unauthenticated users to download other users' private ticket attachments if they obtain the stored file name.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.