Access violation vulnerability in ELEX WordPress HelpDesk & Customer Ticketing System 3.3.1

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress has a security vulnerability that allows unauthorized individuals to change data without proper authorization. This is because the ‘eh_crm_remove_agent’ function does not have a check for capabilities in versions up to and including 3.3.1. This means that attackers who have access at the Subscriber level or higher can remove the role and capabilities of any user with an Administrator, WSDesk Supervisor, or WSDesk Agents role.

Detected in:

ELEX WordPress HelpDesk & Customer Ticketing System fixed vulnerable versions: >= * <= 3.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.