CVE-2025-11456 | ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin eh_crm_new_ticket_post unrestricted upload
A vulnerability classified as critical was found in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System Plugin up to 3.3.1 on WordPress. The affected element is the function eh_crm_new_ticket_post. Executing manipulation can lead to unrestricted upload.
This vulnerability is registered as CVE-2025-11456. It is possible to launch the attack remotely. No exploit is available.