CVE-2026-14862: CWE-862 Missing Authorization in Support Genix
Support Genix WordPress plugin versions before 1.4.48 have a missing authorization vulnerability that allows unauthenticated users to download private support ticket attachments if they know the stored attachment file name. This vulnerability does not require user interaction and has a low severity score.
AI Analysis
Technical Summary
CVE-2026-14862 is a missing authorization vulnerability (CWE-862) in the Support Genix WordPress plugin prior to version 1.4.48. The flaw allows unauthenticated attackers who obtain the stored file name of support ticket attachments to download attachments belonging to other users without proper access checks. This issue arises from improper authorization controls on attachment download functionality.
Potential Impact
An attacker can access private support ticket attachments of other users without authentication, potentially exposing sensitive information. The vulnerability does not allow modification or denial of service and has a low CVSS score of 3.7, indicating limited impact primarily on confidentiality.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict access to attachment file storage locations and monitor for unauthorized access attempts if possible.
CVE-2026-14862: CWE-862 Missing Authorization in Support Genix
Description
Support Genix WordPress plugin versions before 1.4.48 have a missing authorization vulnerability that allows unauthenticated users to download private support ticket attachments if they know the stored attachment file name. This vulnerability does not require user interaction and has a low severity score.
CVSS v3.1
Score 3.7low
Affected software
Support Genix
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-14862 is a missing authorization vulnerability (CWE-862) in the Support Genix WordPress plugin prior to version 1.4.48. The flaw allows unauthenticated attackers who obtain the stored file name of support ticket attachments to download attachments belonging to other users without proper access checks. This issue arises from improper authorization controls on attachment download functionality.
Potential Impact
An attacker can access private support ticket attachments of other users without authentication, potentially exposing sensitive information. The vulnerability does not allow modification or denial of service and has a low CVSS score of 3.7, indicating limited impact primarily on confidentiality.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, restrict access to attachment file storage locations and monitor for unauthorized access attempts if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-06T12:39:48.616Z
- State
- PUBLISHED
Threat ID: 6a6c42b79c2644c7f86e864f
Added to database: 07/31/2026, 06:37:43 UTC
Last enriched: 08/07/2026, 14:45:36 UTC
Last updated: 09/13/2026, 22:01:31 UTC
Views: 29
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.