CVE-2025-12022 | ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin AJAX Endpoint eh_crm_settings_restore_trash authorization

SecurityVulns

A vulnerability was found in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin up to 3.3.1 on WordPress. It has been declared as problematic. This issue affects the function eh_crm_settings_restore_trash of the component AJAX Endpoint. The manipulation results in missing authorization.

This vulnerability is known as CVE-2025-12022. It is possible to launch the attack remotely. No exploit is available.VulDB Recent EntriesRead More