Unauthorized Data Modification in ELEX HelpDesk Plugin for WordPress
CVE-2025-12085

4.3MEDIUM

What is CVE-2025-12085?

The ELEX HelpDesk & Customer Ticketing System plugin for WordPress has a security flaw that allows for unauthorized data modifications. This vulnerability arises from a missing capability check within the 'eh_crm_settings_empty_trash' function. As a result, authenticated users with Subscriber-level roles or higher can exploit this flaw to empty the ticket trash, potentially leading to data loss and unauthorized manipulation of customer support data. It is crucial for administrators using this plugin to update and implement necessary security measures to prevent exploitation.

Affected Version(s)

ELEX WordPress HelpDesk & Customer Ticketing System * <= 3.3.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-12085 : Unauthorized Data Modification in ELEX HelpDesk Plugin for WordPress