Unauthorized Data Access in ilGhera Support System for WooCommerce Plugin by WordPress
CVE-2025-14033
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 May 2026
What is CVE-2025-14033?
The ilGhera Support System for WooCommerce plugin for WordPress has a vulnerability that allows unauthenticated users to access sensitive support ticket information. This occurs due to a missing capability check within the 'get_ticket_content_callback' function, affecting all versions up to and including 1.3.0. Attackers can exploit this flaw by providing a valid ticket ID, leading to the disclosure of private communications and sensitive customer data, making businesses susceptible to serious data breaches.
Affected Version(s)
ilGhera Support System for WooCommerce 0 <= 1.3.0