Impact
The ilGhera Support System for WooCommerce plugin contains a missing capability check in the get_ticket_content_callback function. This flaw enables unauthenticated users to request any support ticket by ID and retrieve its full contents, which may contain confidential customer data and private communications. The weakness is classified as CWE-639, an authorization bypass that leads to the exposure of sensitive information rather than code execution or service disruption.
Affected Systems
All installations of the ghera74 ilGhera Support System for WooCommerce plugin with version numbers up to and including 1.3.0 are affected. Existing deployments of earlier minor releases such as 1.2.6 are also vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating a moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, but the lack of authentication checks means that any visitor can trigger the exploit by supplying a ticket ID. The attack vector is purely HTTP; no privilege escalation or remote code execution is required, yet the impact can result in the disclosure of sensitive customer information.
OpenCVE Enrichment