CVE-2025-12022: ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Restore
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ehcrmsettingsrestoretrash' AJAX endpoint in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to restore all deleted tickets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12022?
CVE-2025-12022 is considered a high severity vulnerability due to the potential for unauthorized modification of data.
How do I fix CVE-2025-12022?
To fix CVE-2025-12022, update the ELEX WordPress HelpDesk & Customer Ticketing System plugin to version 3.3.2 or later.
What versions are affected by CVE-2025-12022?
CVE-2025-12022 affects all versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin up to and including 3.3.1.
How does CVE-2025-12022 impact my WordPress site?
CVE-2025-12022 allows attackers to modify data without authorization, potentially compromising the integrity of your WordPress site.
Is there a workaround for CVE-2025-12022?
There is no official workaround for CVE-2025-12022, and the recommended action is to update the plugin to the latest version.