Access violation vulnerability in ELEX WordPress HelpDesk & Customer Ticketing System 3.3.1

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress has a security flaw that allows unauthorized changes to be made to data. This is because there is no check in place to ensure that only certain users have access to the ‘eh_crm_settings_restore_trash’ feature, which is used to restore deleted tickets. This means that anyone with a Subscriber-level account or higher could potentially restore all deleted tickets.

Detected in:

ELEX WordPress HelpDesk & Customer Ticketing System fixed vulnerable versions: >= * <= 3.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.