Simple Ajax Chat Plugin <= 20220115 - Sensitive Information Disclosure

2022-04-15 10:14
R3N0

Strategic Overview

Status
Patched in 20220216
Affected Version<= 20220115
CVSS5.3Medium
CVECVE-2022-27849
View all Simple Ajax Chat – Add a Fast, Secure Chat Box vulnerabilities

Vulnerability Overview

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

Technical Analysis

REMEDIATION: Update to version 20220216, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C