Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System < 1.4.48 - Unauthenticated Arbitrary File Download
critical
The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Path Traversal in all versions up to 1.4.48 (exclusive). This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensit...
- CVSS:
- 9.1
- Affected:
- up to 1.4.48
- Fixed in:
- 1.4.48
- Disclosed:
- Jul 16, 2026
CVE-2026-15932 on NVD →
Support Genix Lite <= 1.4.47 - Missing Authorization
medium
The Support Genix Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.47. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.4.47
- Fixed in:
- 1.4.48
- Disclosed:
- Jul 16, 2026
CVE-2026-14862 on NVD →
Support Genix <= 1.4.23 - Missing Authorization
medium
The Support Genix – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.23. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.4.23
- Fixed in:
- 1.4.24
- Disclosed:
- Sep 3, 2025
CVE-2025-58635 on NVD →
Support Genix – Helpdesk & Customer Support Ticket System [support-genix-lite] < 1.4.24
unknown
[en] Missing Authorization vulnerability in PalsCode Support Genix allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Support Genix: from n/a through 1.4.23.
- Affected:
- up to 1.4.24
- Fixed in:
- 1.4.24
- Disclosed:
- Sep 3, 2025
CVE-2025-58635 on NVD →
Support Genix <= 1.4.11 - Authenticated (Subscriber+) Insecure Direct Object Reference
medium
The Support Genix – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.4.11 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above...
- CVSS:
- 5.4
- Affected:
- up to 1.4.11
- Fixed in:
- 1.4.12
- Disclosed:
- Mar 27, 2025
CVE-2025-30777 on NVD →
Support Genix – Helpdesk & Customer Support Ticket System [support-genix-lite] < 1.4.12 (closed)
unknown
[en] Authorization Bypass Through User-Controlled Key vulnerability in PalsCode Support Genix allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Support Genix: from n/a through 1.4.11.
- Affected:
- up to 1.4.12
- Fixed in:
- 1.4.12
- Disclosed:
- Mar 27, 2025
CVE-2025-30777 on NVD →
Support Genix – Helpdesk & Customer Support Ticket System [support-genix-lite] < 1.2.4 (closed)
unknown
[en] Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- Apr 18, 2024
CVE-2023-49742 on NVD →
Support Genix <= 1.2.3 - Missing Authorization
medium
The Support Genix plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several functions in all versions up to, and including, 1.2.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform unauthorized actions such as uploading ar...
- CVSS:
- 5.3
- Affected:
- up to 1.2.3
- Fixed in:
- 1.2.4
- Disclosed:
- Apr 16, 2024
CVE-2023-49742 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database