Vulnerabilities > CVE-2022-2834 - Files or Directories Accessible to External Parties vulnerability in Helpful Project Helpful

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
network
low complexity
helpful-project
CWE-552

Summary

The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

Vulnerable Configurations

Part Description Count
Application
Helpful_Project
104