CVE-2025-12169: ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.0 - Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpajaxehcrmsettingsemptyscheduledactions' AJAX Action in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to clear the scheduled triggers option.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12169?
CVE-2025-12169 is considered a high-severity vulnerability due to its potential for unauthorized data modification.
How do I fix CVE-2025-12169?
To fix CVE-2025-12169, update the ELEX WordPress HelpDesk & Customer Ticketing System plugin to the latest version beyond 3.3.0.
What versions are affected by CVE-2025-12169?
All versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin up to and including version 3.3.0 are affected by CVE-2025-12169.
What types of attacks can exploit CVE-2025-12169?
CVE-2025-12169 can be exploited to perform unauthorized modifications of data, potentially allowing attackers to change settings or manipulate ticketing information.
Is there a patch available for CVE-2025-12169?
Yes, a patch is included in newer versions of the ELEX WordPress HelpDesk & Customer Ticketing System plugin released after version 3.3.0.