CVE-2025-47658: WordPress ELEX HelpDesk & Customer Ticketing System plugin <= 3.2.9 - Arbitrary File Upload vulnerability
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Upload a Web Shell to a Web Server.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.2.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47658?
CVE-2025-47658 has a high severity rating due to the potential for unrestricted file uploads, allowing attackers to upload a web shell.
How do I fix CVE-2025-47658?
To fix CVE-2025-47658, update ELEX WordPress HelpDesk & Customer Ticketing System to version 3.2.8 or later.
What types of files can be uploaded in CVE-2025-47658?
CVE-2025-47658 allows the upload of files with dangerous types, including executable scripts and web shells.
Which versions of ELEX WordPress HelpDesk & Customer Ticketing System are affected by CVE-2025-47658?
CVE-2025-47658 affects ELEX WordPress HelpDesk & Customer Ticketing System versions from n/a through 3.2.7.
What impact does CVE-2025-47658 have on website security?
CVE-2025-47658 poses a significant risk to website security by allowing malicious users to gain control over the web server.