CVE-2025-30886: WordPress JS Help Desk plugin <= 2.9.2 - SQL Injection vulnerability
Published Apr 1, 2025
·Updated
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JoomSky JS Help Desk js-support-ticket allows SQL Injection.This issue affects JS Help Desk: from n/a through <= 2.9.2.
Affected Software
3 affected components
joomsky JS Help Desk<=2.9.2
WordPress JS Help Desk<=2.9.2
joomsky Js Help Desk Wordpress<2.9.3
Remediation
Information
Update the WordPress JS Help Desk plugin to the latest available version (at least 2.9.3).
Event History
Apr 1, 2025
CVE Published
via MITRE·05:31 AM
Data Sourced
via MITRE·05:31 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-30886?
CVE-2025-30886 is a high severity vulnerability categorized as SQL Injection in JoomSky JS Help Desk.
2
How do I fix CVE-2025-30886?
To fix CVE-2025-30886, update JoomSky JS Help Desk to the latest version beyond 2.9.2.
3
What types of attacks can CVE-2025-30886 enable?
CVE-2025-30886 can enable attackers to execute arbitrary SQL queries, potentially accessing or modifying sensitive data.
4
Which versions are affected by CVE-2025-30886?
CVE-2025-30886 affects all versions of JoomSky JS Help Desk up to and including version 2.9.2.
5
What is the impact of exploiting CVE-2025-30886?
Exploiting CVE-2025-30886 can lead to unauthorized data exposure, data loss, or data corruption in the affected system.