Record summary

CVE-2022-27849 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List<= 20220115 to ≤ 20220115affected

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Simple Ajax Chat <20220116 - Sensitive Information Disclosure vulnerabilityCVSS 7.5

WordPress Simple Ajax Chat before 20220216 is vulnerable to sensitive information disclosure. The plugin does not properly restrict access to the exported data via the sac-export.csv file, which could allow unauthenticated users to access it.

Impact

An attacker can exploit this vulnerability to gain access to sensitive information, such as user credentials or private messages.

Remediation

Update to the latest version of the WordPress Simple Ajax Chat plugin to fix the vulnerability.

WeaknessesCWE-200
Authorsrandom-robbie
Template tagscvecve2022wpwordpresswp-plugindisclosureplugin-planetvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:plugin-planet:simple_ajax_chat:*:*:*:*:*:wordpress:*:*
Google: inurl:/wp-content/plugins/simple-ajax-chat/

Source: ProjectDiscovery

References

3