PT-2025-48655 · WordPress · Elex Wordpress Helpdesk & Customer Ticketing System

Athiwat Tiprasaharn

·

Published

2025-12-02

·

Updated

2025-12-02

·

CVE-2025-13534

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ELEX WordPress HelpDesk & Customer Ticketing System versions up to and including 3.3.2
Description The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is susceptible to a privilege escalation issue. Missing authorization checks on the eh crm edit agent AJAX action allow authenticated attackers with Contributor-level access or higher to elevate their privileges. This enables unauthorized access to helpdesk administrator capabilities, including ticket management, settings configuration, agent administration, and sensitive customer data.
Recommendations Update ELEX WordPress HelpDesk & Customer Ticketing System to a version later than 3.3.2.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-13534

Affected Products

Elex Wordpress Helpdesk & Customer Ticketing System