Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

ELEX WordPress HelpDesk & Customer Ticketing System — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in ELEX WordPress HelpDesk & Customer Ticketing System, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities for the ELEX WordPress HelpDesk & Customer Ticketing System plugin, categorized by weakness type and associated tags. It collects a comprehensive list of security issues affecting this specific product, ranging from critical privilege escalation flaws to less severe information disclosure and cross-site scripting weaknesses. The data spans several years of security advisories, reflecting the evolution of threat landscapes and the vendor’s response over time. By aggregating these findings, the page serves as a centralized reference for security professionals, developers, and site administrators. Users can track the vendor’s history of security advisories to understand how quickly they address reported issues and patch their code. Furthermore, the page allows for a deeper understanding of specific weakness classes by showing how different attacks have been exploited within this ecosystem. Visitors can also look up the full vulnerability history of the ELEX WordPress HelpDesk & Customer Ticketing System to assess its overall security posture and risk level. This aggregation helps in making informed decisions about plugin usage, updating schedules, and mitigation strategies. It provides context beyond individual CVE entries, highlighting patterns in vulnerability discovery and resolution. The information is presented neutrally to support technical analysis rather than promotional narratives. It enables users to compare security practices across similar WordPress plugins and evaluate the effectiveness of current security measures. This resource is essential for maintaining the integrity of WordPress-based support systems.

Vendor: elextensions

CVE ID Title CVSS Severity Published
CVE-2026-48964 WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.6 - SQL Injection vulnerability CWE-89 8.5 High 2026-06-15
CVE-2025-68837 WordPress ELEX WordPress HelpDesk & Customer Ticketing System plugin <= 3.3.5 - Broken Access Control vulnerability CWE-862 6.5 Medium 2026-02-20
CVE-2025-14079 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to Authenticated (Subscriber+) Settings Update CWE-862 5.3 Medium 2026-02-05
CVE-2025-9343 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High 2025-12-21
CVE-2025-13534 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action CWE-269 6.3 Medium 2025-12-02
CVE-2025-10039 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client' CWE-639 4.3 Medium 2025-11-21
CVE-2025-10054 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal CWE-862 4.3 Medium 2025-11-21
CVE-2025-11456 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload CWE-434 9.8 Critical 2025-11-21
CVE-2025-12169 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.0 - Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion CWE-862 4.3 Medium 2025-11-21
CVE-2025-12022 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Restore CWE-862 4.3 Medium 2025-11-21
CVE-2025-12023 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Ticket Restore CWE-862 4.3 Medium 2025-11-21
CVE-2025-12085 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Empty CWE-862 4.3 Medium 2025-11-21
CVE-2025-47658 WordPress ELEX HelpDesk & Customer Ticketing System plugin <= 3.2.9 - Arbitrary File Upload vulnerability CWE-434 9.9 Critical 2025-05-23
CVE-2024-12171 ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.6 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation CWE-862 8.8 High 2025-02-01

All 14 known CVE vulnerabilities affecting ELEX WordPress HelpDesk & Customer Ticketing System with full Chinese analysis, references, and POCs where available.