CVE-2026-19806: Support Genix <= 1.4.52 - Authenticated (Subscriber+) Authentication Bypass to Administrator Account Takeover via 'p' Parameter Forged Guest Token

Published Sep 1, 2026
·
Updated

The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 1.4.52 via the guestticketlogin() function and its p parameter. This is due to the site-wide AES-256-CBC encryption key being derived from only three two-digit wprand(10, 99) values and a Unix timestamp via md5() — yielding approximately 19.5 bits of entropy — combined with a deterministic IV derived from the password, no authentication tag on the ciphertext, and no capability check, nonce, or session validation on the publicly reachable /sgnix/?p=<token> endpoint. This makes it possible for authenticated attackers, with subscriber-level access and above, who can obtain a single legitimate guest ticket token as a known-plaintext oracle and bound the plugin activation timestamp, to exhaust the ~729,000-candidate keyspace entirely offline, recover the site-wide encryption key, and forge a self-consistent {ticketid, ticketuser} token targeting any administrator-owned ticket. Submitting the forged token to the unprotected endpoint causes wpsetauthcookie() to be called for that administrator, granting the attacker full administrative access to the WordPress site.

Affected Software

1 affected component
WordPress plugin Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System<=1.4.52

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress to a version that resolves this vulnerability.

    Fixed in 1.4.52

Event History

Sep 1, 2026
CVE Published
via MITRE·04:27 AM
Data Sourced
via MITRE·04:27 AM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203