Wsdesk
Vendor:
First CVE: Feb 1, 2025 · Active for 1 year
10
Total CVEs
More Total CVEs than 89% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wsdesk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2025
17 months ago
Most Recent CVE
Dec 2, 2025
237 days ago
CVE Severity & Scoring
Wsdesk10 CVEs
60%
30%
10%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low9 (90.0%)
High0 (0.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11456CRITICAL The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the eh_crm_new_ticket_po | Nov 21, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-13534HIGH The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missi | Dec 2, 2025 | 8.8 | 27 | NO | NO |
CVE-2024-12171HIGH The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'eh_crm_agent_add_user' | Feb 1, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-47658HIGH Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allow | May 23, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-12169MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_eh | Nov 21, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-12023MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_crm_rest | Nov 21, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-12022MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_set | Nov 21, 2025 | 4.3 | 18 | NO | NO |
CVE-2025-10054MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_rem | Nov 21, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-10039MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.2.9 via the ' | Nov 21, 2025 | 4.3 | 17 | NO | NO |
CVE-2025-12085MEDIUM The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'eh_crm_set | Nov 21, 2025 | 4.3 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Wsdesk
Top CWEs
Versions
No cataloged versions.