
ELEX WordPress HelpDesk & Customer Ticketing System Security & Risk Analysis
wordpress.org/plugins/elex-helpdesk-customer-support-ticket-systemELEX WordPress HelpDesk & Customer Ticketing System offers top-notch features for the best customer support experience.
Is ELEX WordPress HelpDesk & Customer Ticketing System Safe to Use in 2026?
Mostly Safe
Score 82/100ELEX WordPress HelpDesk & Customer Ticketing System is generally safe to use. 13 past CVEs were resolved. Keep it updated.
The plugin "elex-helpdesk-customer-support-ticket-system" version 3.3.6 presents a mixed security posture. On the positive side, the plugin demonstrates a strong commitment to secure coding practices, with 90% of SQL queries utilizing prepared statements and 90% of output properly escaped. It also includes a substantial number of nonce and capability checks, indicating an awareness of WordPress security mechanisms. However, the large number of unprotected AJAX handlers (112 out of 119) and one unprotected REST API route represent a significant attack surface that could be exploited by unauthenticated users.
The static analysis also revealed the presence of dangerous functions, specifically `unserialize`, which can be a vector for deserialization vulnerabilities if user-controlled data is unserialized without proper sanitization. The taint analysis further highlights concerns, with 12 out of 25 analyzed flows having unsanitized paths and 7 of these being classified as high severity. This suggests potential vulnerabilities where user input is not adequately validated or neutralized before being used in sensitive operations.
The plugin's vulnerability history, with 13 known CVEs including 1 critical and 3 high severity, is a major red flag. While there are currently no unpatched CVEs, the recurring nature of critical and high-severity vulnerabilities, especially those related to Cross-Site Scripting, Improper Privilege Management, and Authorization Bypass, indicates a persistent pattern of security weaknesses. The most recent vulnerability being in 2026 is also concerning, suggesting that past vulnerabilities have been significant enough to require substantial security fixes. In conclusion, while the plugin employs some good security practices, the large unprotected attack surface, potential for deserialization vulnerabilities, high taint flow severity, and a history of critical and high-severity CVEs necessitate caution and prompt review of its security controls.
Key Concerns
- Large attack surface without auth checks
- Unprotected REST API routes
- Presence of dangerous unserialize function
- High severity taint flows
- History of critical CVEs
- History of high severity CVEs
- Bundled outdated jQuery library
ELEX WordPress HelpDesk & Customer Ticketing System Security Vulnerabilities
CVEs by Year
Severity Breakdown
13 total CVEs
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization to Authenticated (Subscriber+) Settings Update
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.5 - Missing Authorization
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.4 - Unauthenticated Stored Cross-Site Scripting
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.2 - Authenticated (Contributor+) Privilege Escalation via eh_crm_edit_agent AJAX Action
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Unauthenticated Arbitrary File Upload
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Ticket Restore
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Empty
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Trash Restore
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.0 - Missing Authorization to Authenitcated (Subscriber+) to Scheduled Trigger Deletion
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Role Removal
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Insecure Direct Object Reference via 'eh_crm_ticket_single_view_client'
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.9 - Authenticated (Subscriber+) Arbitrary File Upload
ELEX WordPress HelpDesk & Customer Ticketing System <= 3.2.6 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
ELEX WordPress HelpDesk & Customer Ticketing System Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ELEX WordPress HelpDesk & Customer Ticketing System Attack Surface
AJAX Handlers 119
REST API Routes 1
Shortcodes 3
WordPress Hooks 33
Scheduled Events 3
Maintenance & Trust
ELEX WordPress HelpDesk & Customer Ticketing System Maintenance & Trust
Maintenance Signals
Community Trust
ELEX WordPress HelpDesk & Customer Ticketing System Alternatives
Awesome Support – WordPress HelpDesk & Support Plugin
awesome-support
The most versatile and feature-rich help desk and support plugin for WordPress. Provide awesome support directly from your WordPress site.
Chimney Rock Support Tickets
chimney-rock-support-tickets
Create and manage support tickets for your customers or subscribers with ease.
Nirweb support
nirweb-support
NirWeb support is a great help desk and support plugin for WordPress with full support of WooCommerce
Customer Support Ticket System & Helpdesk Plugin for WordPress
wp-ticket
Create a support ticket system in WordPress. Manage customer inquiries, agents, priorities, and more with this flexible helpdesk plugin.
Helpdesk Support Ticket System for WooCommerce
support-ticket-system-for-woocommerce
WordPress ticket system - Manage customer queries and issues on your WordPress eShop with helpdesk WooCommerce support ticket system
ELEX WordPress HelpDesk & Customer Ticketing System Developer Profile
22 plugins · 28K total installs
How We Detect ELEX WordPress HelpDesk & Customer Ticketing System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/css/admin-style.css/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/css/wsdesk-frontend.css/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/css/wsdesk-woo-frontend.css/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/css/wsdesk-woo-frontend.css?ver=1.0/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/admin-script.js/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/wsdesk-frontend.js/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/wsdesk-frontend.js?ver=1.0/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/wsdesk-frontend.js?ver=1.1/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/admin-script.js/wp-content/plugins/elex-helpdesk-customer-support-ticket-system/assets/js/wsdesk-frontend.jselex-helpdesk-customer-support-ticket-system/assets/css/admin-style.css?ver=elex-helpdesk-customer-support-ticket-system/assets/css/wsdesk-frontend.css?ver=elex-helpdesk-customer-support-ticket-system/assets/css/wsdesk-woo-frontend.css?ver=elex-helpdesk-customer-support-ticket-system/assets/js/admin-script.js?ver=elex-helpdesk-customer-support-ticket-system/assets/js/wsdesk-frontend.js?ver=HTML / DOM Fingerprints
wsdesk-wrap-divwsdesk-widget-title<!-- wsdesk_helpdesk_shortcode -->data-wsdesk-shortcodewsdesk_frontend_objwsdesk_frontend_param/wp-json/wsdesk/v1/attachment/wp-json/wsdesk/v1/ticket/wp-json/wsdesk/v1/comment[wsdesk_helpdesk_form][wsdesk_helpdesk_list][wsdesk_helpdesk_view]