CVE-2022-2834

MEDIUM

Helpful WP <4.5.26 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

References (1)

Core 1
Core References
Exploit, Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37ae

Scores

CVSS v3 5.3
EPSS 0.0077
EPSS Percentile 50.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-552
Status published
Products (1)
helpful_project/helpful < 4.5.26
Published Oct 17, 2022
Tracked Since Feb 18, 2026