Executive brief
The ilGhera Support System for WooCommerce plugin for WordPress, which manages customer support tickets for online stores, contains a security flaw that allows unauthorized access to private data. An attacker can view any support ticket, including sensitive customer information and private communications, without needing to log in. This could lead to the exposure of personal customer details and proprietary business interactions.
Technical details
The ilGhera Support System for WooCommerce plugin for WordPress is vulnerable to an Insecure Direct Object Reference (IDOR) / Authorization Bypass due to a missing capability check on the 'get_ticket_content_callback' function. This function, used to retrieve ticket data, does not verify if the requesting user has the appropriate permissions or ownership of the ticket. An unauthenticated attacker can exploit this by sending a request with a specific ticket ID to view the contents of any support ticket. The vulnerability affects all versions up to and including 1.3.0; version 1.3.1 appears to contain a fix based on the provided reference links.
Affected products
- ilGhera Support System for WooCommerce Up to, and including, 1.3.0
Timeline
- 2026-05-13: disclosed: NVD publication date
- 2026-05-13: advisory: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support-system.php
- https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.2.6/includes/class-wc-support-system.php
- https://plugins.trac.wordpress.org/browser/wc-support-system/tags/1.3.1/includes/class-wc-support-system.php
- https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-system.php
- https://plugins.trac.wordpress.org/browser/wc-support-system/trunk/includes/class-wc-support-system.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/40ceea17-ec60-4775-8495-e2f7643d1b7c?source=cve