CVE-2025-13534
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13534 is a privilege escalation vulnerability in the ELEX WordPress HelpDesk & Customer Ticketing System plugin (WSDesk) for WordPress. It affects all versions up to and including 3.3.2, and was disclosed on December 2, 2025. The flaw allows authenticated attackers with Contributor-level access or higher to escalate their WSDesk privileges to full helpdesk administrator capabilities. It carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is missing authorization checks on the eh_crm_edit_agent AJAX action, classified as CWE-269 (Improper Privilege Management). An authenticated attacker with at least Contributor-level WordPress access can send a crafted AJAX request to this endpoint without any capability verification, allowing them to modify their own WSDesk agent role from limited "Reply Tickets" permissions to full helpdesk administrator access. The vulnerable code path is visible in the plugin's class-crm-ajax-functions-two.php file (Wordfence, WordPress Trac).

Impact

Successful exploitation grants an attacker full helpdesk administrator capabilities within the WSDesk plugin, including unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data. This represents a complete compromise of the helpdesk system's confidentiality, integrity, and availability within its scope. While the vulnerability does not directly escalate WordPress site-wide privileges, exposure of customer PII and support ticket contents poses significant data breach risk (Wordfence, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a low-privilege authenticated account (Contributor level), which lowers the barrier for abuse on sites with open user registration (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the ELEX WordPress HelpDesk & Customer Ticketing System plugin version 3.3.2 or earlier, using tools like WPScan or by checking the plugin's readme.txt file at wp-content/plugins/elex-helpdesk-customer-support-ticket-system/readme.txt.
  2. Obtain low-privilege access: Register or obtain credentials for a Contributor-level (or higher) WordPress account on the target site. On sites with open registration, this may require only a valid email address.
  3. Craft malicious AJAX request: As the authenticated Contributor, send a POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter set to eh_crm_edit_agent and a payload that modifies the attacker's WSDesk agent role to administrator.
  4. Achieve privilege escalation: Due to the missing authorization check, the server processes the request and elevates the attacker's WSDesk role to full helpdesk administrator without verifying permissions.
  5. Exploit elevated access: Use the newly gained administrator privileges to access all support tickets and customer data, modify helpdesk settings, manage other agents, or exfiltrate sensitive customer information (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-admin/admin-ajax.php with action=eh_crm_edit_agent from Contributor-level user accounts; unusual access to WSDesk admin endpoints from non-administrator user sessions.
  • Logs: WordPress access logs showing repeated AJAX calls to admin-ajax.php with the eh_crm_edit_agent action from low-privilege user accounts; sudden changes to WSDesk agent role assignments in the database.
  • Application: Unexpected WSDesk agent accounts with administrator-level permissions that were not explicitly granted by a site administrator; unauthorized changes to helpdesk settings or agent configurations.
  • Database: Modifications to WSDesk agent role fields in the WordPress database (wp_usermeta or plugin-specific tables) not corresponding to legitimate administrative actions.

Mitigation and workarounds

Update the ELEX WordPress HelpDesk & Customer Ticketing System plugin to version 3.3.3 or later, which contains the fix for the missing authorization check (Wordfence). If immediate patching is not feasible, consider disabling the plugin temporarily or restricting Contributor-level account registration to trusted users only. Additionally, review existing WSDesk agent role assignments to identify any unauthorized privilege escalations that may have already occurred.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management