plugin

Helpful Vulnerabilities

8 known security issues reported for the Helpful WordPress plugin. Most recent disclosed May 3, 2023.

3 medium

Running Helpful on your site? Check whether your installed version is affected.

Scan your site free

Helpful [helpful] < 4.5.15 (closed)

unknown

Update the WordPress Helpful plugin to the latest available version (at least 4.5.15). An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress Helpful Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has be...

Affected:
up to 4.5.15
Fixed in:
4.5.15
Disclosed:
May 3, 2023

Helpful [helpful] < 4.5.26 (closed)

unknown

[en] The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings

Affected:
up to 4.5.26
Fixed in:
4.5.26
Disclosed:
Oct 17, 2022

CVE-2022-2834 on NVD →

Helpful <= 4.5.25 - Sensitive Information Disclosure

medium

The Helpful plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.5.25. Specifically, feedback and logs are stored in predictable locations with guessable file names. This could allow unauthenticated attackers to extract sensitive user data.

CVSS:
5.3
Affected:
up to 4.5.25
Fixed in:
4.5.26
Disclosed:
Sep 26, 2022

CVE-2022-2834 on NVD →

Helpful <= 4.5.14 - Authorization Bypass to Repeat Voting

medium

The Helpful plugin for WordPress is vulnerable to repeat voting in versions up to, and including, 4.5.14 due to insufficient voting verification/authorization. This makes it possible for authenticated attackers to vote more than once in polls created with the plugin.

CVSS:
4.3
Affected:
up to 4.5.14
Fixed in:
4.5.15
Disclosed:
Aug 16, 2022

Helpful [helpful] < 4.5.15 (closed)

unknown

The Helpful plugin for WordPress is vulnerable to repeat voting in versions up to, and including, 4.5.14 due to insufficient voting verification/authorization. This makes it possible for authenticated attackers to vote more than once in polls created with the plugin.

Affected:
up to 4.5.15
Fixed in:
4.5.15
Disclosed:
Aug 16, 2022

Helpful [helpful] < 4.4.59 (closed)

unknown

[en] The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

Affected:
up to 4.4.59
Fixed in:
4.4.59
Disclosed:
Nov 17, 2021

CVE-2021-24841 on NVD →

Helpful <= 4.4.58 - Admin+ Stored Cross-Site Scripting

medium

The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed

CVSS:
5.5
Affected:
up to 4.4.59
Fixed in:
4.4.59
Disclosed:
Oct 18, 2021

CVE-2021-24841 on NVD →

Helpful [helpful] < 4.5.15 (closed)

unknown

The plugin allowed users to vote more than once, which could allow attackers to increase votes drastically on some posts

Affected:
up to 4.5.15
Fixed in:
4.5.15

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database