WordPress Plugin Vulnerabilities

Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization

Description

The plugin does not properly authorize access to support-ticket attachment downloads, allowing unauthenticated users who obtain the stored attachment file name to download other users' private ticket attachments.

Proof of Concept

Affects Plugins

Fixed in 1.4.48

References

Classification

Type
NO AUTHORISATION
CWE
CVSS

Miscellaneous

Original Researcher
Alessandro Greco aka Aleff, Giovanbattista Ianni (University of Calabria - UNICAL)
Submitter
Alessandro Greco aka Aleff
Verified
Yes

Timeline

Publicly Published
2026-07-16 (about 10 days ago)
Added
2026-07-16 (about 10 days ago)
Last Updated
2026-07-16 (about 10 days ago)

Other