The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ghera74
Ghera74 ilghera Support System For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Ghera74
Ghera74 ilghera Support System For Woocommerce Wordpress Wordpress wordpress |
Wed, 13 May 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID. | |
| Title | ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-05-13T05:29:36.689Z
Updated: 2026-05-13T10:20:56.843Z
Reserved: 2025-12-04T14:59:13.237Z
Link: CVE-2025-14033
Updated: 2026-05-13T10:18:28.142Z
Status : Deferred
Published: 2026-05-13T06:16:12.747
Modified: 2026-05-13T14:43:46.717
Link: CVE-2025-14033
No data.