What the vulnerability does
01Description
Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.2.
Explanation of Vulnerability in Simple Terms
02Summary
The Helpdesk Support Ticket System for WooCommerce plugin does not properly check user permissions before allowing access to sensitive ticket data. An unauthenticated attacker can read support tickets and their contents without logging in or having any account. This affects all versions up to 2.1.2.
What an attacker can do
03Attacker Capabilities
Read support tickets and their contents without authentication.
Potential impact on your site
04Site Impact
Customer support tickets containing sensitive information are exposed to anyone on the internet.
Conditions required to exploit
05Prerequisites
Network access to the site; no authentication or user interaction required.
Key dates
06Disclosure timeline
March 25, 2026
CVE published
April 28, 2026
Record updated