CVE-2022-2834
Last modified
CVE-2022-2834 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings. EPSS estimates a 0.77% chance of exploitation in the next 30 days.
Description
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Helpful Project | Helpful | < 4.5.26 |
References
- https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37aeExploit, Third Party Advisory
- https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37aeExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2834?
How severe is CVE-2022-2834?
How do I fix CVE-2022-2834?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-28328A vulnerability has been identified in SCALANCE W1788-1 M12 …7.5
- CVE-2022-28329A vulnerability has been identified in SCALANCE W1788-1 M12 …6.5
- CVE-2022-2833Endless Infinite loop in Blender-thumnailing due to logical …7.5
- CVE-2022-28330Apache HTTP Server 2.4.53 and earlier on Windows may read be…5.3
- CVE-2022-28331On Windows, Apache Portable Runtime 1.7.0 and earlier may wr…9.8
- CVE-2022-28339Trend Micro HouseCall for Home Networks version 5.3.1302 and…7.8
- CVE-2022-28345The Signal app before 5.34 for iOS allows URI spoofing via R…7.5
- CVE-2022-28346An issue was discovered in Django 2.2 before 2.2.28, 3.2 bef…9.8
- CVE-2022-28347A SQL injection issue was discovered in QuerySet.explain() i…9.8
- CVE-2022-28348Arm Mali GPU Kernel Driver (Midgard r4p0 through r31p0, Bifr…9.8
- CVE-2022-28349Arm Mali GPU Kernel Driver has a use-after-free: Midgard r28…9.8
- CVE-2022-2835A flaw was found in coreDNS. This flaw allows a malicious us…4.4
Are you affected by CVE-2022-2834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
