CVE-2025-31053 HIGH

CVE-2025-31053: WordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion Vulnerability

Vendor Quantumcloud
Product KBx Pro Ultimate
Weakness CWE-22 · Path traversal
Published May 23, 2025
Last update April 28, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

What the vulnerability does

01Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a through < 8.0.5.

Explanation of Vulnerability in Simple Terms

02Summary

KBx Pro Ultimate versions up to 8.0.5 contain a path traversal vulnerability that allows authenticated users to cause a denial of service by accessing files outside the intended directory. The vulnerability requires low-level authentication and network access. The scope is changed, meaning the impact may extend beyond the vulnerable component itself.

What an attacker can do

03Attacker Capabilities

Authenticated user can make the site unavailable by traversing the file system and triggering a denial of service.

Potential impact on your site

04Site Impact

Site availability can be disrupted by authenticated users with low privileges exploiting path traversal.

Conditions required to exploit

05Prerequisites

Attacker must have a low-level user account on the site; no user interaction required.

Key dates

06Disclosure timeline

May 23, 2025 CVE published
April 28, 2026 Record updated