Unauthorized Data Modification in ELEX HelpDesk Plugin for WordPress
CVE-2025-12085
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 November 2025
What is CVE-2025-12085?
The ELEX HelpDesk & Customer Ticketing System plugin for WordPress has a security flaw that allows for unauthorized data modifications. This vulnerability arises from a missing capability check within the 'eh_crm_settings_empty_trash' function. As a result, authenticated users with Subscriber-level roles or higher can exploit this flaw to empty the ticket trash, potentially leading to data loss and unauthorized manipulation of customer support data. It is crucial for administrators using this plugin to update and implement necessary security measures to prevent exploitation.
Affected Version(s)
ELEX WordPress HelpDesk & Customer Ticketing System * <= 3.3.1