Description
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_restore_trash' AJAX endpoint in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to restore all deleted tickets.
Published: 2025-11-21
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized restoration of deleted tickets by authenticated (Subscriber+) users
Action: Patch
AI Analysis

Impact

The vulnerability arises from a missing capability check on the 'eh_crm_settings_restore_trash' AJAX endpoint in the ELEX WordPress HelpDesk & Customer Ticketing System plugin. Because the endpoint lacks proper authorization validation, any authenticated user with Subscriber-level access and higher can invoke the endpoint to restore all previously deleted tickets. This enables an attacker to recover deleted ticket data, potentially exposing sensitive customer information and compromising the integrity of the support system. The weakness, classified as CWE-862 Missing Authorization Check, is a moderate privilege escalation flaw with a CVSS score of 4.3.

Affected Systems

All installations of the ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress up to and including version 3.3.1 are affected. The issue is tied to the plugin's core directory, specifically the AJAX handler for restoring trashed tickets. No other versions or products from other vendors are listed as affected.

Risk and Exploitability

The risk is moderate due to the CVSS score of 4.3 and a very low EPSS (<1%), indicating that automated exploitation is unlikely. The flaw is not listed in the CISA KEV catalog, suggesting it has not been widely exploited in the wild. The attack vector is local to a user who is authenticated with the site; an attacker needs to know the AJAX endpoint URL or use the plugin’s UI to trigger the restore. An authenticated Subscriber or higher‑level role can perform the action, so the impact is confined to the data within the ticketing system rather than the entire WordPress installation.

Generated by OpenCVE AI on April 22, 2026 at 16:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor‑released patch or update the ELEX plugin to the latest available version.
  • Remove or disable the restore capability for Subscriber‑level and lower roles using the WordPress role editor or by adding custom code that revokes the capability.
  • Restrict access to the 'eh_crm_settings_restore_trash' AJAX endpoint for Subscriber roles by configuring your web server firewall, .htaccess rules, or a security plugin that limits AJAX requests based on user role.

Generated by OpenCVE AI on April 22, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Elula
Elula wsdesk
CPEs cpe:2.3:a:elula:wsdesk:*:*:*:*:free:wordpress:*:*
Vendors & Products Elula
Elula wsdesk

Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Elextensions
Elextensions elex Wordpress Plugin
Wordpress
Wordpress wordpress
Vendors & Products Elextensions
Elextensions elex Wordpress Plugin
Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Nov 2025 05:45:00 +0000

Type Values Removed Values Added
Description The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_settings_restore_trash' AJAX endpoint in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to restore all deleted tickets.
Title ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Restore
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Elextensions Elex Wordpress Plugin
Elula Wsdesk
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:10:38.123Z

Reserved: 2025-10-21T14:44:41.416Z

Link: CVE-2025-12022

cve-icon Vulnrichment

Updated: 2025-11-21T14:54:00.409Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-21T06:15:47.557

Modified: 2025-12-03T18:28:25.610

Link: CVE-2025-12022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T16:45:21Z

Weaknesses