
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12169 is a Missing Authorization vulnerability in the ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress. It affects all versions up to and including 3.3.0, and was published on November 21, 2025. The flaw allows authenticated attackers with Subscriber-level access or above to perform unauthorized data modification by exploiting a missing capability check on the wp_ajax_eh_crm_settings_empty_scheduled_actions AJAX action. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the plugin's AJAX action wp_ajax_eh_crm_settings_empty_scheduled_actions does not perform a capability check before executing, allowing any authenticated WordPress user — including those with the lowest default role (Subscriber) — to invoke it. An attacker simply needs to send a crafted authenticated AJAX request to the WordPress admin-ajax endpoint targeting this action, which will clear the plugin's scheduled triggers option without any privilege validation. No complex exploitation technique or special configuration is required beyond having a valid WordPress account (Wordfence, WordPress Changeset).
Successful exploitation allows an authenticated attacker to clear the scheduled triggers/actions configured in the ELEX HelpDesk plugin, potentially disrupting automated ticket processing workflows and customer support operations. There is no direct confidentiality impact (no data exposure) and no availability impact beyond disruption of plugin scheduling logic. The integrity impact is limited to the plugin's scheduled actions configuration, but could interrupt critical helpdesk automation for affected WordPress sites (Wordfence, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Wordfence). The EPSS score is approximately 0.026% (0.000260), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a valid WordPress account (Subscriber-level or above), which limits the attack surface compared to unauthenticated vulnerabilities.
/wp-admin/admin-ajax.php) with the parameter action=eh_crm_settings_empty_scheduled_actions./wp-admin/admin-ajax.php with the body parameter action=eh_crm_settings_empty_scheduled_actions from unexpected or low-privilege user accounts.admin-ajax.php with the above action from Subscriber-level user sessions.Upgrade the ELEX WordPress HelpDesk & Customer Ticketing System plugin to version 3.3.1 or later, which includes the fix adding the missing capability check (WordPress Changeset). As an interim measure, limit WordPress user account creation and restrict Subscriber-level registrations if not required. Monitor plugin logs and scheduled action configurations for unexpected changes. No alternative workaround is documented beyond applying the patch.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."