ELEX WordPress HelpDesk and Customer Ticketing System Missing Authorization Vulnerability

Vulnerability

A missing authorization vulnerability has been identified in the ELEX WordPress HelpDesk & Customer Ticketing System plugin, affecting all versions through 3.3.5. The vulnerability arises from inadequate capability checks in the 'eh_crm_ticket_general' function, coupled with a shared nonce accessible to low-privileged users. This flaw enables authenticated attackers with Subscriber-level access and above to alter global WSDesk settings via the 'eh_crm_ticket_general' AJAX action.

Impact

Exploitation of this vulnerability allows authenticated users with Subscriber-level access and above to modify global WSDesk settings, potentially leading to unauthorized changes in the application's behavior or user management.

Remediation

Users are advised to update the plugin to version 3.3.6 or a newer patched version.

Added: Feb 5, 2026, 10:27 AM
Updated: Feb 5, 2026, 3:15 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
2.5
exploitability
6.1
remediation
7.7
relevance
2.5
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.