Описание
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.5.26 (исключая)
cpe:2.3:a:helpful_project:helpful:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 66%
0.00516
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-552
Связанные уязвимости
CVSS3: 5.3
github
больше 3 лет назад
The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
EPSS
Процентиль: 66%
0.00516
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-552