← العودة للجدول
CVE-2026-19806
CVE-2026-19806 — The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Suppor
📅 2026-09-01
🟠 High 🔥 No NVD Vulnerability WordPress CVSS 8.8

📋 الوصف الكامل

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the `guest_ticket_login()` function and its `p` parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-d

💻 الأنظمة المتأثرة

WordPress | Oracle

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-19806

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v1.4.52

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←