SecAlerts
e

elex

Security Risk Profile

52
/100
medium

Security Risk Score

Comprehensive risk assessment based on 14 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from December 24, 2024 to present

14
Total CVEs
5
Critical+High
1
Exploited
3
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
3
Critical/High
Risk Level
52/100
medium
⚠️ 1 Active Exploits🆕 1Fresh (<7d)📈 1 in Last 30 Days

Severity Distribution

Critical
3
High
2
Medium
9
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
2

Age Distribution

Common Weaknesses (CWE)

1
SQL Injection
3
2
Malicious File Upload
2

Most Affected Products

1. ELEX WordPress HelpDesk & Customer Ticketing System10
2. Elula Wsdesk Wordpress10
3. ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes2
4. ELEX WooCommerce Google Shopping (Google Product Feed)1
5. ELEX WooCommerce Dynamic Pricing and Discounts1

Recent Vulnerabilities

See more →
CVE-2026-40800
CVSS 9.3critical

WordPress ELEX WooCommerce Advanced Bulk Edit Products, Prices & Attributes plugin <= 1.5.3 - SQL Injection vulnerability

Oct 10, 2026🔧 No Patch
CVE-2025-13534
CVSS 8.8high

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action

Dec 2, 2025🔧 No Patch
CVE-2025-10039
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client'

Nov 21, 2025🔧 No Patch
CVE-2025-10054
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal

Nov 21, 2025🔧 No Patch
CVE-2025-11456
CVSS 9.8critical

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload

Nov 21, 2025
CVE-2025-12169
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.0 - Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion

Nov 21, 2025🔧 No Patch
CVE-2025-12022
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Restore

Nov 21, 2025🔧 No Patch
CVE-2025-12023
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Ticket Restore

Nov 21, 2025🔧 No Patch
CVE-2025-12085
CVSS 4.3medium

ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Empty

Nov 21, 2025🔧 No Patch
CVE-2025-10046
CVSS 4.9medium

ELEX WooCommerce Google Shopping (Google Product Feed) <= 1.4.3 - Authenticated (Admin+) SQL Inejction

Sep 6, 2025⚠ Exploited🔧 No Patch

Monitor elex in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.