cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forelex-helpdesk-customer-support-ticket-system elex-helpdesk-customer-support-ticket-system

Direction: descending
May 14, 2025

ELEX WordPress HelpDesk & Customer Ticketing System # CVE-2025-47658

CVE, Research URL

CVE-2025-47658

Date
-
Research Description
ELEX WordPress HelpDesk &amp; Customer Ticketing System [elex-helpdesk-customer-support-ticket-system] <= 3.2.7 (unfixed) CVE-2025-47658
Affected versions
Min -, max -.
Status
vulnerable
Feb 02, 2025

ELEX WordPress HelpDesk &amp; Customer Ticketing System # CVE-2024-12171

CVE, Research URL

CVE-2024-12171

Date
Feb 01, 2025
Research Description
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' AJAX action in all versions up to, and including, 3.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new administrative user accounts.
Affected versions
Min -, max -.
Status
vulnerable