cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forelex-helpdesk-customer-support-ticket-system elex-helpdesk-customer-support-ticket-system

Direction: ascending
Feb 02, 2025

ELEX WordPress HelpDesk & Customer Ticketing System # CVE-2024-12171

CVE, Research URL

CVE-2024-12171

Date
Feb 01, 2025
Research Description
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new administrative user accounts.
Affected versions
max 3.2.7.
Status
vulnerable
May 14, 2025

ELEX WordPress HelpDesk & Customer Ticketing System # CVE-2025-47658

CVE, Research URL

CVE-2025-47658

Date
May 23, 2025
Research Description
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System allows Upload a Web Shell to a Web Server. This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through 3.2.7.
Affected versions
max 3.2.7.
Status
vulnerable