Description
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.
Published: 2026-05-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ilGhera Support System for WooCommerce plugin contains a missing capability check in the get_ticket_content_callback function. This flaw enables unauthenticated users to request any support ticket by ID and retrieve its full contents, which may contain confidential customer data and private communications. The weakness is classified as CWE-639, an authorization bypass that leads to the exposure of sensitive information rather than code execution or service disruption.

Affected Systems

All installations of the ghera74 ilGhera Support System for WooCommerce plugin with version numbers up to and including 1.3.0 are affected. Existing deployments of earlier minor releases such as 1.2.6 are also vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating a moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, but the lack of authentication checks means that any visitor can trigger the exploit by supplying a ticket ID. The attack vector is purely HTTP; no privilege escalation or remote code execution is required, yet the impact can result in the disclosure of sensitive customer information.

Generated by OpenCVE AI on May 13, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ilGhera Support System for WooCommerce plugin to version 1.3.1 or later.
  • If an immediate upgrade is not possible, implement a temporary capability check that restricts the get_ticket_content endpoint to authenticated users only by adding PHP code to the theme’s functions.php or using a plugin that enforces user roles.
  • Audit all support tickets that may have been exposed and notify affected customers if any unauthorized access likely occurred.

Generated by OpenCVE AI on May 13, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 13 May 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Ghera74
Ghera74 ilghera Support System For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Ghera74
Ghera74 ilghera Support System For Woocommerce
Wordpress
Wordpress wordpress

Wed, 13 May 2026 06:00:00 +0000

Type Values Removed Values Added
Description The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.
Title ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Ghera74 Ilghera Support System For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-05-13T10:20:56.843Z

Reserved: 2025-12-04T14:59:13.237Z

Link: CVE-2025-14033

cve-icon Vulnrichment

Updated: 2026-05-13T10:18:28.142Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T06:16:12.747

Modified: 2026-05-13T14:43:46.717

Link: CVE-2025-14033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T10:34:47Z

Weaknesses