{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/support-genix/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:support_genix:helpdesk_ai_chatbot_knowledge_base_customer_support_ticketing_system:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-19806"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Support Genix – Helpdesk, AI Chatbot, Knowledge Base \u0026 Customer Support Ticketing System (\u003c= 1.4.52)"],"_cs_severities":["high"],"_cs_tags":["wordpress","authentication-bypass","web-application-attack"],"_cs_type":"advisory","_cs_vendors":["Support Genix"],"content_html":"\u003cp\u003eThe Support Genix plugin for WordPress (all versions up to and including 1.4.52) contains a critical cryptographic weakness in its \u003ccode\u003eguest_ticket_login()\u003c/code\u003e function. The plugin derives its site-wide AES-256-CBC encryption key using low-entropy inputs, specifically three two-digit random integers and a Unix timestamp hashed with \u003ccode\u003emd5()\u003c/code\u003e. This results in approximately 19.5 bits of entropy, which allows an attacker with subscriber-level access to exhaust the 729,000-candidate keyspace offline.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is exposed via the publicly accessible \u003ccode\u003e/sgnix/?p=\u0026lt;token\u0026gt;\u003c/code\u003e endpoint, which lacks nonces, capability checks, or session validation. By obtaining a single legitimate guest ticket token, an attacker can perform a known-plaintext attack to recover the site-wide encryption key. Once the key is recovered, the attacker can forge a ticket token for any administrator-owned ticket. Submitting this forged token to the endpoint triggers \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e for the target administrator, granting the attacker full administrative access to the site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains a legitimate guest ticket token to serve as a known-plaintext oracle.\u003c/li\u003e\n\u003cli\u003eAttacker retrieves site metadata to estimate the plugin activation timestamp.\u003c/li\u003e\n\u003cli\u003eAttacker uses the known-plaintext and estimated timestamp to perform an offline brute-force attack on the 729,000-candidate keyspace.\u003c/li\u003e\n\u003cli\u003eAttacker successfully recovers the site-wide AES-256-CBC encryption key.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a forged ticket token referencing a target administrator user ID and ticket ID.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP GET request to the \u003ccode\u003e/sgnix/?p=\u003c/code\u003e endpoint with the forged token as the parameter.\u003c/li\u003e\n\u003cli\u003eThe plugin fails to validate the token's origin or authenticity and invokes \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e for the administrator.\u003c/li\u003e\n\u003cli\u003eThe WordPress site grants the attacker administrative privileges, completing the account takeover.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated or low-privileged attackers to gain full administrative access to WordPress sites running the vulnerable plugin. This enables complete site takeover, including the ability to exfiltrate data, modify content, install malicious themes or plugins, and establish persistence, affecting any organization relying on the Support Genix plugin for helpdesk operations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the Support Genix WordPress plugin to a version released after 1.4.52 to remediate the cryptographic flaw. Until patching is possible, restrict access to the \u003ccode\u003e/sgnix/\u003c/code\u003e endpoint via web application firewall (WAF) rules or server-side configuration to prevent unauthenticated access. Monitor web server access logs for anomalous GET requests to \u003ccode\u003e/sgnix/\u003c/code\u003e that contain unusually long or repetitive \u003ccode\u003ep\u003c/code\u003e parameter values.\u003c/p\u003e\n","date_modified":"2026-09-01T07:03:45Z","date_published":"2026-09-01T07:03:45Z","id":"https://feed.craftedsignal.io/briefs/2026-09-support-genix-auth-bypass/","summary":"The Support Genix WordPress plugin is vulnerable to authentication bypass and administrator account takeover due to a weak cryptographic implementation in the guest ticket login feature.","title":"Authentication Bypass in Support Genix WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-support-genix-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Support Genix","version":"https://jsonfeed.org/version/1.1"}