CVE-2025-12085: ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Empty
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ehcrmsettingsemptytrash' function in all versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to empty the ticket trash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12085?
CVE-2025-12085 has a medium severity level due to the potential for unauthorized data modification.
How do I fix CVE-2025-12085?
To fix CVE-2025-12085, update the ELEX WordPress HelpDesk & Customer Ticketing System plugin to version 3.3.2 or higher.
Who is affected by CVE-2025-12085?
CVE-2025-12085 affects all versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin up to and including version 3.3.1.
What are the consequences of exploiting CVE-2025-12085?
Exploiting CVE-2025-12085 may allow attackers to modify settings and potentially manipulate customer data without proper authorization.
Is there a workaround for CVE-2025-12085?
Currently, there is no known workaround for CVE-2025-12085; the best practice is to update the plugin to the latest version.