ELEX WordPress HelpDesk & Customer Ticketing System
cpe:2.3:a:elula:wsdesk:*:*:*:*:wordpress:*:*
- <= 3.3.5
A missing authorization vulnerability has been identified in the ELEX WordPress HelpDesk & Customer Ticketing System plugin, affecting all versions through 3.3.5. The vulnerability arises from inadequate capability checks in the 'eh_crm_ticket_general' function, coupled with a shared nonce accessible to low-privileged users. This flaw enables authenticated attackers with Subscriber-level access and above to alter global WSDesk settings via the 'eh_crm_ticket_general' AJAX action.
Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to modify global WSDesk settings, potentially leading to unauthorized changes in the application's behavior or user management.
Users are advised to update the plugin to version 3.3.6 or a newer patched version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.