CVE-2025-30880: WordPress JS Help Desk plugin <= 2.9.2 - Broken Access Control vulnerability
Published Apr 1, 2025
·Updated
Missing Authorization vulnerability in JoomSky JS Help Desk js-support-ticket allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JS Help Desk: from n/a through <= 2.9.2.
Affected Software
3 affected components
joomsky JS Help Desk<=2.9.2
WordPress JS Help Desk plugin<=2.9.2
joomsky Js Help Desk Wordpress<2.9.3
Remediation
Information
Update the WordPress JS Help Desk plugin to the latest available version (at least 2.9.3).
Event History
Apr 1, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30880?
CVE-2025-30880 is classified as a critical severity vulnerability due to its potential for unauthorized access.
2
Which software versions are affected by CVE-2025-30880?
CVE-2025-30880 affects JoomSky JS Help Desk versions up to and including 2.9.2.
3
How do I fix CVE-2025-30880?
To fix CVE-2025-30880, users should upgrade the JoomSky JS Help Desk to the latest version beyond 2.9.2.
4
What type of vulnerability is CVE-2025-30880?
CVE-2025-30880 is identified as a Missing Authorization vulnerability related to incorrectly configured access control.
5
Can CVE-2025-30880 lead to data exposure?
Yes, CVE-2025-30880 can lead to unauthorized access to sensitive information if exploited.