plugin

Knowledgebase Helpdesk Pro Vulnerabilities

4 known security issues reported for the Knowledgebase Helpdesk Pro WordPress plugin. Most recent disclosed Oct 22, 2025.

2 high

Running Knowledgebase Helpdesk Pro on your site? Check whether your installed version is affected.

Scan your site free

KBx Pro Ultimate [knowledgebase-helpdesk-pro] <= 8.0.5 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Object Injection.This issue affects KBx Pro Ultimate: from n/a through <= 8.0.5.

Affected:
up to 8.0.5
Fix:
No patched version reported
Disclosed:
Oct 22, 2025

CVE-2025-60232 on NVD →

KBx Pro Ultimate <= 8.0.5 - Unauthenticated PHP Object Injection

high

The KBx Pro Ultimate plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 8.0.5 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software. If a POP chain is present...

CVSS:
8.1
Affected:
up to 8.0.5
Fix:
No patched version reported
Disclosed:
Jul 15, 2025

CVE-2025-60232 on NVD →

KBx Pro Ultimate [knowledgebase-helpdesk-pro] <= 7.9.8 (unfixed)

unknown

[en] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a before 8.0.5.

Affected:
up to 7.9.8
Fix:
No patched version reported
Disclosed:
May 23, 2025

CVE-2025-31053 on NVD →

KBx Pro Ultimate < 8.0.5 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The KBx Pro Ultimate plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and excluding, 8.0.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary files on the server, which can easily l...

CVSS:
8.1
Affected:
up to 8.0.5
Fixed in:
8.0.5
Disclosed:
May 21, 2025

CVE-2025-31053 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database