← WordPress Vulnerabilities
WordPress security by component

ELEX WordPress HelpDesk & Customer Ticketing System

ELEX WordPress HelpDesk & Customer Ticketing System is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: elex-helpdesk-customer-support-ticket-system

CVE-2026-48964: ELEX WordPress HelpDesk & Customer Ticketing System: SQL injection

ELEX WordPress HelpDesk & Customer Ticketing System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.3.6.

PublishedJun 15, 2026
Known safe version3.3.7
Safe version
Jun 15, 2026 CVE-2026-48964
ELEX WordPress HelpDesk & Customer Ticketing System: SQL injection
ELEX WordPress HelpDesk & Customer Ticketing System is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 3.3.6.
3.3.7
CVE8.5
NVDPending
Feb 20, 2026 CVE-2025-68837
ELEX WordPress HelpDesk & Customer Ticketing System: A security weakness
ELEX WordPress HelpDesk & Customer Ticketing System is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Feb 05, 2026 CVE-2025-14079
ELEX WordPress HelpDesk & Customer Ticketing System: A security weakness
ELEX WordPress HelpDesk & Customer Ticketing System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 02, 2025 CVE-2025-13534
ELEX WordPress HelpDesk & Customer Ticketing System: Privilege escalation or authentication bypass
ELEX WordPress HelpDesk & Customer Ticketing System is affected by privilege escalation or authentication bypass. Exploitation requires at least contributor-level access. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE6.3
NVD8.8
Nov 21, 2025 CVE-2025-10054
ELEX WordPress HelpDesk & Customer Ticketing System: A security weakness
ELEX WordPress HelpDesk & Customer Ticketing System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVD4.3
Nov 21, 2025 CVE-2025-10039
ELEX WordPress HelpDesk & Customer Ticketing System: A security weakness
ELEX WordPress HelpDesk & Customer Ticketing System is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 21, 2025 CVE-2025-11456
ELEX WordPress HelpDesk & Customer Ticketing System: Dangerous file upload
ELEX WordPress HelpDesk & Customer Ticketing System is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.8
NVDPending