5.3

CVE-2022-2834

Exploit

Helpful < 4.5.26 - Information Disclosure

Helpful <= 4.5.25 - Sensitive Information Disclosure

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
Mögliche Gegenmaßnahme
Helpful: Update to version 4.5.26, or a newer patched version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Helpful ProjectHelpful SwPlatformwordpress Version < 4.5.26
Weitere Schwachstelleninformationen
SystemWordPress Plugin
Produkt Helpful
Version *-4.5.25
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.507
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
134c704f-9b21-4f2e-91b3-4a467353bcc0 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37ae
Third Party Advisory
Exploit
https://www.wordfence.com/threat-intel/vulnerabilities/id/56b4d824-96b8-40e6-97b5-17748d13574a
Third Party Advisory