CVE-2025-30901: WordPress JS Help Desk plugin <= 2.9.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JoomSky JS Help Desk js-support-ticket allows PHP Local File Inclusion.This issue affects JS Help Desk: from n/a through <= 2.9.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30901?
CVE-2025-30901 has been classified as a significant security vulnerability due to its potential for PHP Local File Inclusion.
How do I fix CVE-2025-30901?
To fix CVE-2025-30901, upgrade the JoomSky JS Help Desk to version 2.9.3 or later where the vulnerability is patched.
What systems are affected by CVE-2025-30901?
CVE-2025-30901 affects JoomSky JS Help Desk versions prior to 2.9.3 and the WordPress JS Help Desk plugin versions up to 2.9.2.
What is PHP Local File Inclusion as related to CVE-2025-30901?
PHP Local File Inclusion in CVE-2025-30901 allows an attacker to include files from the local filesystem, which can lead to unauthorized code execution.
Is there a patch available for CVE-2025-30901?
Yes, a patch is available in version 2.9.3 of JoomSky JS Help Desk that addresses the vulnerability.