
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13534 is a privilege escalation vulnerability in the ELEX WordPress HelpDesk & Customer Ticketing System plugin (WSDesk) for WordPress. It affects all versions up to and including 3.3.2, and was disclosed on December 2, 2025. The flaw allows authenticated attackers with Contributor-level access or higher to escalate their WSDesk privileges to full helpdesk administrator capabilities. It carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Red Hat CVE).
The root cause is missing authorization checks on the eh_crm_edit_agent AJAX action, classified as CWE-269 (Improper Privilege Management). An authenticated attacker with at least Contributor-level WordPress access can send a crafted AJAX request to this endpoint without any capability verification, allowing them to modify their own WSDesk agent role from limited "Reply Tickets" permissions to full helpdesk administrator access. The vulnerable code path is visible in the plugin's class-crm-ajax-functions-two.php file (Wordfence, WordPress Trac).
Successful exploitation grants an attacker full helpdesk administrator capabilities within the WSDesk plugin, including unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data. This represents a complete compromise of the helpdesk system's confidentiality, integrity, and availability within its scope. While the vulnerability does not directly escalate WordPress site-wide privileges, exposure of customer PII and support ticket contents poses significant data breach risk (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.027%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires only a low-privilege authenticated account (Contributor level), which lowers the barrier for abuse on sites with open user registration (Wordfence).
wp-content/plugins/elex-helpdesk-customer-support-ticket-system/readme.txt./wp-admin/admin-ajax.php) with the action parameter set to eh_crm_edit_agent and a payload that modifies the attacker's WSDesk agent role to administrator./wp-admin/admin-ajax.php with action=eh_crm_edit_agent from Contributor-level user accounts; unusual access to WSDesk admin endpoints from non-administrator user sessions.admin-ajax.php with the eh_crm_edit_agent action from low-privilege user accounts; sudden changes to WSDesk agent role assignments in the database.wp_usermeta or plugin-specific tables) not corresponding to legitimate administrative actions.Update the ELEX WordPress HelpDesk & Customer Ticketing System plugin to version 3.3.3 or later, which contains the fix for the missing authorization check (Wordfence). If immediate patching is not feasible, consider disabling the plugin temporarily or restricting Contributor-level account registration to trusted users only. Additionally, review existing WSDesk agent role assignments to identify any unauthorized privilege escalations that may have already occurred.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."