ELEX WordPress HelpDesk Plugin Data Modification Vulnerability (CVE-2025-12085) — Medium Severity Explained

Overview

A security flaw has been found in the ELEX WordPress HelpDesk & Customer Ticketing System plugin, which is widely used for customer support on WordPress websites. This vulnerability, identified as CVE-2025-12085, allows unauthorized individuals to perform certain actions they shouldn’t be able to. Specifically, even users with basic subscriber-level access can empty the ticket trash, meaning they can delete support tickets that have been marked for removal without proper authorization. This is due to a missing check in the plugin that should restrict who can perform this action.

CVE Details

  • Product: ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress
  • Published: November 21, 2025
  • Severity: Medium
  • Status: Analyzed

Affected Products

The vulnerability impacts all versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin (specifically `wsdesk` by `elula`) up to and including version 3.3.1. If you are using any version within this range, your system may be at risk.

Current Status

This vulnerability has been analyzed and publicly disclosed. While the core issue stems from a missing capability check, it’s important for users to understand the implications and apply any available fixes.

Severity Level

The severity of this issue is rated as MEDIUM. This means that while it doesn’t allow for full control over your website, it does permit unauthorized data manipulation. An attacker could, for example, intentionally delete old support tickets from the trash, which could disrupt record-keeping or customer support operations if not noticed promptly. The risk is primarily to data integrity within the ticketing system.

Possible Solutions

The vulnerability exists in versions up to and including 3.3.1. Users should always ensure their plugins are updated to the latest available version. Based on the information, a patch has likely been released in versions *after* 3.3.1 to address this flaw. We strongly recommend that all users of the ELEX WordPress HelpDesk & Customer Ticketing System plugin update to the newest version as soon as possible to secure their installations. Regularly updating all WordPress plugins and themes is a crucial security practice.

References

https://plugins.trac.wordpress.org/changeset/3399391/elex-helpdesk-customer-support-ticket-system/trunk/includes/class-crm-ajax-functions-two.php
https://www.wordfence.com/threat-intel/vulnerabilities/id/89696d1c-8e6e-402a-9d7a-03fe0f364a72?source=cve

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.