๐Ÿ” CVE Alert

CVE-2025-13534

MEDIUM 6.3

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited "Reply Tickets" permissions to full helpdesk administrator capabilities, gaining unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data.

CWE CWE-269
Vendor elextensions
Product elex wordpress helpdesk & customer ticketing system
Published Dec 2, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for elextensions elex wordpress helpdesk & customer ticketing system

Be the first to know when new medium vulnerabilities affecting elextensions elex wordpress helpdesk & customer ticketing system are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

elextensions / ELEX WordPress HelpDesk & Customer Ticketing System
0 โ‰ค 3.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/3541794b-7c8a-42f8-9688-7f3dbbb08e58?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/elex-helpdesk-customer-support-ticket-system/trunk/includes/class-crm-ajax-functions-two.php#L9 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/elex-helpdesk-customer-support-ticket-system/tags/3.3.2/includes/class-crm-ajax-functions-two.php#L9 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/stm-gallery/trunk/stmgallery_v.0.9.php#L121

Credits

Athiwat Tiprasaharn