CVE Explorer
CVE-2026-15932
The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download route, allowing unauthenticated attackers to read arbitrary files with an allowlisted extension — including other users' private ticket attachments — from the server.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Support Genix","vendor":"Unknown","versions":[{"lessThan":"1.4.48","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f1287ff48b5448672ab8ea6bd634897072cfc3fca200a15dffb144cd1c5097e3 · sha256:f935350cf4663866… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f1287ff48b5448672ab8ea6bd634897072cfc3fca200a15dffb144cd1c5097e3 · sha256:f935350cf4663866… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/d03887a5-1a0e-4097-8dfa-7899aae8a6d5/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f1287ff48b5448672ab8ea6bd634897072cfc3fca200a15dffb144cd1c5097e3 · sha256:f935350cf4663866… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.