Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Upload a Web Shell to a Web Server.This issue affects ELEX WordPress HelpDesk & Customer Ticketing System: from n/a through <= 3.2.9.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elula | Wsdesk | < 3.3.0 |
Related Weaknesses (CWE)
References
- https://patchstack.com/database/Wordpress/Plugin/elex-helpdesk-customer-support-Third Party Advisory
FAQ
What is CVE-2025-47658?
CVE-2025-47658 is a vulnerability with a CVSS score of 9.9 (CRITICAL). Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketing System elex-helpdesk-customer-support-ticket-system allows Upload a Web Shell...
How severe is CVE-2025-47658?
CVE-2025-47658 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-47658?
Check the references section above for vendor advisories and patch information. Affected products include: Elula Wsdesk.