---
id: CVE-2025-14033
title: >-
  The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable
  to unauthorized access of data due to a missing capability check on the
  'get_ticket_content_callback' function in all versions up to, and including,
  1.3.0
summary: >-
  The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable
  to unauthorized access of data due to a missing capability check on the
  'get_ticket_content_callback' function in all versions up to, and including,
  1.3.0. Thi…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
published: '2026-05-13'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-14033'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support-system.php#L643
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support-system.php#L68
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php#L780
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-system.php#L643
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-system.php#L68
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea17-ec60-4775-8495-e2f7643d1b7c?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00256
epssPercentile: 0.15584
ingestedAt: '2026-09-30T22:27:27.790Z'
---

## Overview

The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'get_ticket_content_callback' function in all versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to view any support ticket content, including sensitive customer information and private communications, by providing a ticket ID.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
