The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
References
| Link | Resource |
|---|---|
| https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37ae | Exploit Third Party Advisory |
Configurations
Information
Published : 2022-10-17 05:15
Updated : 2022-10-21 09:31
NVD link : CVE-2022-2834
Mitre link : CVE-2022-2834
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
helpful_project
- helpful


