📦 Wsdesk

by Elula

🔍 What is Wsdesk?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-11456

CRITICAL CVSS 9.8 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has a critical vulnerability allowing unauthenticated attackers to upload arbitrary files due to missing file type validation. This can lead to remote code execution...

CVE-2024-12171

HIGH CVSS 8.8 Feb 1, 2025

The ELEX WordPress HelpDesk & Customer Ticketing System plugin has a privilege escalation vulnerability that allows authenticated attackers with Subscriber-level access or higher to create new adminis...

CVE-2025-13534

MEDIUM CVSS 6.3 Dec 2, 2025

The ELEX WordPress HelpDesk plugin has a privilege escalation vulnerability that allows authenticated users with Contributor-level access or higher to elevate their permissions to full helpdesk admini...

CVE-2025-10039

MEDIUM CVSS 4.3 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has an Insecure Direct Object Reference vulnerability that allows authenticated users with Subscriber-level access or higher to read all support tickets. This affect...

CVE-2025-10054

MEDIUM CVSS 5.3 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to remove administrator and agent roles from any user. This...

CVE-2025-12169

MEDIUM CVSS 4.3 Nov 21, 2025

This vulnerability allows authenticated WordPress users with Subscriber-level access or higher to clear scheduled triggers in the ELEX HelpDesk plugin. Attackers can disrupt automated ticket workflows...

CVE-2025-12022

MEDIUM CVSS 4.3 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to restore all deleted tickets. This affects all WordPress ...

CVE-2025-12023

MEDIUM CVSS 4.3 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has an authorization bypass vulnerability that allows authenticated users with Subscriber-level access or higher to restore tickets without proper permission checks....

CVE-2025-12085

MEDIUM CVSS 4.3 Nov 21, 2025

The ELEX WordPress HelpDesk plugin has an authorization vulnerability that allows authenticated users with Subscriber-level access or higher to permanently delete tickets from the trash. This affects ...