PT-2026-1402 · WordPress · Ilghera Woocommerce Support System
CVE-2025-14034
·
Publicado
2026-01-06
·
Atualizado
2026-01-06
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
ilGhera Support System for WooCommerce plugin versions prior to 1.2.7
Description
The ilGhera Support System for WooCommerce plugin for WordPress has a flaw that allows unauthorized modification and data loss. A missing capability check in the
delete single ticket callback and change ticket status callback functions allows authenticated attackers with Subscriber-level access or higher to delete support tickets and change their status.Recommendations
Update the ilGhera Support System for WooCommerce plugin to version 1.2.7 or later.
Correção
LPE
Missing Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ilghera Woocommerce Support System