CVE-2025-13534 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - authenticated (co...

CVE-2025-13534 - ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - authenticated (co...

CVE ID : CVE-2025-13534 Published : Dec. 2, 2025, 9:15 a.m. | 46 minutes ago Description : The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited

CVE Details

Published
Dec. 2, 2025
Affected Product: WordPress
Impact: Privilege Escalation

Source: Telegram CVE Monitor