Overview
A security flaw has been found in the ELEX WordPress HelpDesk & Customer Ticketing System plugin, which is widely used for customer support on WordPress websites. This vulnerability, identified as CVE-2025-12085, allows unauthorized individuals to perform certain actions they shouldn’t be able to. Specifically, even users with basic subscriber-level access can empty the ticket trash, meaning they can delete support tickets that have been marked for removal without proper authorization. This is due to a missing check in the plugin that should restrict who can perform this action.
CVE Details
- Product: ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress
- Published: November 21, 2025
- Severity: Medium
- Status: Analyzed
Affected Products
The vulnerability impacts all versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin (specifically `wsdesk` by `elula`) up to and including version 3.3.1. If you are using any version within this range, your system may be at risk.
Current Status
This vulnerability has been analyzed and publicly disclosed. While the core issue stems from a missing capability check, it’s important for users to understand the implications and apply any available fixes.
Severity Level
The severity of this issue is rated as MEDIUM. This means that while it doesn’t allow for full control over your website, it does permit unauthorized data manipulation. An attacker could, for example, intentionally delete old support tickets from the trash, which could disrupt record-keeping or customer support operations if not noticed promptly. The risk is primarily to data integrity within the ticketing system.
Possible Solutions
The vulnerability exists in versions up to and including 3.3.1. Users should always ensure their plugins are updated to the latest available version. Based on the information, a patch has likely been released in versions *after* 3.3.1 to address this flaw. We strongly recommend that all users of the ELEX WordPress HelpDesk & Customer Ticketing System plugin update to the newest version as soon as possible to secure their installations. Regularly updating all WordPress plugins and themes is a crucial security practice.
References
https://plugins.trac.wordpress.org/changeset/3399391/elex-helpdesk-customer-support-ticket-system/trunk/includes/class-crm-ajax-functions-two.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/89696d1c-8e6e-402a-9d7a-03fe0f364a72?source=cve


