What is CVE-2026-15932?
This vulnerability exists in the Support Genix WordPress plugin before version 1.4.48. It allows unauthenticated attackers to perform a directory traversal attack via the ticket-attachment download route, reading arbitrary files with allowed extensions, including other users' private ticket attachments. Immediate update to the latest plugin version is recommended.
Azərbaycanca: Bu boşluq Support Genix WordPress plaginində (1.4.48-dən əvvəlki versiyalarda) aşkarlanıb. Doğrulanmamış hücumçuya 'directory traversal' zəifliyi vasitəsilə serverdən icazə verilən fayl genişlənmələrinə malik ixtiyari faylları, o cümlədən digər istifadəçilərin şəxsi ticket əlavələrini oxumağa imkan verir. Plagini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the Support Genix plugin are affected by CVE-2026-15932?
All versions prior to 1.4.48 are affected by this directory traversal vulnerability.
What files can an attacker access by exploiting CVE-2026-15932?
An unauthenticated attacker can read arbitrary files with allowed extensions on the server, including other users' private ticket attachments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.