CVE-2022-27849
WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability
Record summary
CVE-2022-27849 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 20, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple Ajax Chat (WordPress plugin)Browse Jeff Starr / Simple Ajax Chat (WordPress plugin) | CVE List | <= 20220115 to ≤ 20220115 | affected |
Nuclei templates
1ProjectDiscoveryHIGHWordPress Simple Ajax Chat <20220116 - Sensitive Information Disclosure vulnerabilityCVSS 7.5
WordPress Simple Ajax Chat before 20220216 is vulnerable to sensitive information disclosure. The plugin does not properly restrict access to the exported data via the sac-export.csv file, which could allow unauthenticated users to access it.
Impact
An attacker can exploit this vulnerability to gain access to sensitive information, such as user credentials or private messages.
Remediation
Update to the latest version of the WordPress Simple Ajax Chat plugin to fix the vulnerability.
Source: ProjectDiscovery