KBx Pro Ultimate [knowledgebase-helpdesk-pro] <= 8.0.5 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.
- Affected:
- up to 8.0.5
- Fix:
- No patched version reported
- Disclosed:
- Oct 22, 2025
CVE-2025-60232 on NVD →
KBx Pro Ultimate <= 8.0.5 - Unauthenticated PHP Object Injection
high
The KBx Pro Ultimate plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present...
- CVSS:
- 8.1
- Affected:
- up to 8.0.5
- Fix:
- No patched version reported
- Disclosed:
- Jul 15, 2025
CVE-2025-60232 on NVD →
KBx Pro Ultimate [knowledgebase-helpdesk-pro] <= 7.9.8 (unfixed)
unknown
[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a before 8.0.5.
- Affected:
- up to 7.9.8
- Fix:
- No patched version reported
- Disclosed:
- May 23, 2025
CVE-2025-31053 on NVD →
KBx Pro Ultimate < 8.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The KBx Pro Ultimate plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and excluding, 8.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily l...
- CVSS:
- 8.1
- Affected:
- up to 8.0.5
- Fixed in:
- 8.0.5
- Disclosed:
- May 21, 2025
CVE-2025-31053 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database