CVE-2025-31053: WordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion Vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a before 8.0.5.
Other sources
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in quantumcloud KBx Pro Ultimate knowledgebase-helpdesk-pro allows Path Traversal.This issue affects KBx Pro Ultimate: from n/a through < 8.0.5.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31053?
CVE-2025-31053 is classified as a high-severity vulnerability due to its potential to allow unauthorized access to sensitive files.
How do I fix CVE-2025-31053?
To fix CVE-2025-31053, you should update your QuantumCloud KBx Pro Ultimate to the latest version above 7.9.8.
What does CVE-2025-31053 affect?
CVE-2025-31053 affects QuantumCloud KBx Pro Ultimate versions up to and including 7.9.8.
What is a Path Traversal vulnerability like CVE-2025-31053?
A Path Traversal vulnerability like CVE-2025-31053 allows attackers to access files outside the intended directory, potentially leading to data breaches.
Who is the vendor for the CVE-2025-31053 vulnerability?
The vendor for the CVE-2025-31053 vulnerability is QuantumCloud, which developed the KBx Pro Ultimate software.