CVE-2025-14033: ilGhera Support System for WooCommerce <= 1.3.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'getticketcontentcallback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14033?
CVE-2025-14033 has a high severity due to the potential for unauthorized access to sensitive information.
How do I fix CVE-2025-14033?
To fix CVE-2025-14033, update the ilGhera Support System for WooCommerce plugin to version 1.3.1 or later.
What type of vulnerability is CVE-2025-14033?
CVE-2025-14033 is a missing authorization vulnerability allowing unauthorized access to sensitive information.
Who is affected by CVE-2025-14033?
Users of the ilGhera Support System for WooCommerce plugin for WordPress version 1.3.0 or earlier are affected by CVE-2025-14033.
What can attackers do with CVE-2025-14033?
Attackers can exploit CVE-2025-14033 to view sensitive ticket content without proper authorization.