Helpful <= 4.5.25 - Sensitive Information Disclosure
2022-09-26 00:00
Aleksi KistauriStrategic Overview
Vulnerability Overview
The Helpful plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.5.25. Specifically, feedback and logs are stored in predictable locations with guessable file names. This could allow unauthenticated attackers to extract sensitive user data.
Technical Analysis
REMEDIATION: Update to version 4.5.26, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C