5.3
CVE-2022-2834
- EPSS 0.52%
- Veröffentlicht 17.10.2022 12:15:09
- Zuletzt bearbeitet 13.05.2025 20:15:22
- Quelle contact@wpscan.com
- CVE-Watchlists
- Unerledigt
Helpful <= 4.5.25 - Sensitive Information Disclosure
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
Mögliche Gegenmaßnahme
Helpful: Update to version 4.5.26, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Helpful
Version
*-4.5.25
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Helpful Project ≫ Helpful SwPlatformwordpress Version < 4.5.26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.52% | 0.662 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-552 Files or Directories Accessible to External Parties
The product makes files or directories accessible to unauthorized actors, even though they should not be.