Executive brief
The ELEX WordPress HelpDesk & Customer Ticketing System plugin, used for managing customer support requests, contains a security flaw that allows users with basic 'Subscriber' accounts to interfere with the site's database. An attacker could exploit this to steal sensitive customer information or disrupt support operations. Business owners should update the plugin to version 3.3.7 immediately to prevent unauthorized data access.
Technical details
A SQL injection vulnerability exists in the ELEX WordPress HelpDesk & Customer Ticketing System plugin due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is accessible to authenticated users with 'Subscriber' privileges or higher. By sending specially crafted requests, a remote attacker can execute arbitrary SQL queries against the underlying database. This can lead to the unauthorized extraction of sensitive data or potential impact on database availability. The issue is resolved in version 3.3.7.
Affected products
- ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6
Timeline
- 2026-04-14: other: Vulnerability reported by Mukhlis Amien
- 2026-06-02: advisory: Patchstack published advisory and mitigation rules
- 2026-06-15: disclosed: NVD published CVE-2026-48964