PT-2022-18965 · WordPress · Helpful Wordpress Plugin
Aleksi Kistauri
·
Published
2022-10-17
·
Updated
2025-05-13
·
CVE-2022-2834
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Helpful WordPress plugin versions prior to 4.5.26
Description
The issue allows attackers to download exported logs and feedbacks due to them being stored in a publicly accessible location with guessable names. This could lead to the retrieval of sensitive information such as IP addresses, names, and email addresses, depending on the plugin's settings.
Recommendations
For versions prior to 4.5.26, update to version 4.5.26 or later to resolve the issue. As a temporary workaround, consider restricting access to the exported logs and feedbacks to minimize the risk of exploitation.
Exploit
Fix
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Helpful Wordpress Plugin