Helpful < 4.5.26 - Information Disclosure
CVE-2022-2834

5.3MEDIUM

Key Information:

Vendor
Wordpress
Status
Vendor
CVE Published:
17 October 2022

Summary

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

Affected Version(s)

Helpful 0 < 4.5.26

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aleksi Kistauri
WPScan
.