Helpful <= 4.5.25 - Sensitive Information Disclosure

2022-09-26 00:00
Aleksi Kistauri

Strategic Overview

Status
Patched in 4.5.26
Affected PluginHelpful
Affected Version<= 4.5.25
CVSS5.3Medium
CVECVE-2022-2834
View all Helpful vulnerabilities

Vulnerability Overview

The Helpful plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.5.25. Specifically, feedback and logs are stored in predictable locations with guessable file names. This could allow unauthenticated attackers to extract sensitive user data.

Technical Analysis

REMEDIATION: Update to version 4.5.26, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C