CVE-2025-14079Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This is due to missing capability checks on the eh_crm_ticket_general function combined with a shared nonce that is exposed to low-privileged users. This makes it possible for authenticated attackers, with Subscriber-level access and above, to modify global WSDesk settings via the `eh_crm_ticket_general` AJAX action.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-05: 2Technical Details · 2026-02-05: 202-05
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2025-14079 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.3.5. This … https://www.cve.org/CVERecord?id=CVE-2025-14079

    Post summary

    The statement reports that the ELEX WordPress HelpDesk plugin suffers from a missing authorization flaw in versions up to 3.3.5, but provides no further technical detail, PoC, patch, or exploitation evidence.

    00010303
    56.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-14079 Missing Authorization Vulnerability in ELEX WordPress HelpDesk Plugin <= 3.3.5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-14079

    Post summary

    The post announces CVE-2025-14079 as a missing authorization flaw in ELEX WordPress HelpDesk Plugin versions up to 3.3.5, without providing PoC, exploitation details, or remediation information.

    0000068
    4.0K followersView on X

Explore more