Helpful [helpful] < 4.5.15 (closed)
unknown
Update the WordPress Helpful plugin to the latest available version (at least 4.5.15).
An unknown person discovered and reported this Bypass Vulnerability vulnerability in WordPress Helpful Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has be...
- Affected:
- up to 4.5.15
- Fixed in:
- 4.5.15
- Disclosed:
- May 3, 2023
Helpful [helpful] < 4.5.26 (closed)
unknown
[en] The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
- Affected:
- up to 4.5.26
- Fixed in:
- 4.5.26
- Disclosed:
- Oct 17, 2022
CVE-2022-2834 on NVD →
Helpful <= 4.5.25 - Sensitive Information Disclosure
medium
The Helpful plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 4.5.25. Specifically, feedback and logs are stored in predictable locations with guessable file names. This could allow unauthenticated attackers to extract sensitive user data.
- CVSS:
- 5.3
- Affected:
- up to 4.5.25
- Fixed in:
- 4.5.26
- Disclosed:
- Sep 26, 2022
CVE-2022-2834 on NVD →
Helpful <= 4.5.14 - Authorization Bypass to Repeat Voting
medium
The Helpful plugin for WordPress is vulnerable to repeat voting in versions up to, and including, 4.5.14 due to insufficient voting verification/authorization. This makes it possible for authenticated attackers to vote more than once in polls created with the plugin.
- CVSS:
- 4.3
- Affected:
- up to 4.5.14
- Fixed in:
- 4.5.15
- Disclosed:
- Aug 16, 2022
Helpful [helpful] < 4.5.15 (closed)
unknown
The Helpful plugin for WordPress is vulnerable to repeat voting in versions up to, and including, 4.5.14 due to insufficient voting verification/authorization. This makes it possible for authenticated attackers to vote more than once in polls created with the plugin.
- Affected:
- up to 4.5.15
- Fixed in:
- 4.5.15
- Disclosed:
- Aug 16, 2022
Helpful [helpful] < 4.4.59 (closed)
unknown
[en] The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- Affected:
- up to 4.4.59
- Fixed in:
- 4.4.59
- Disclosed:
- Nov 17, 2021
CVE-2021-24841 on NVD →
Helpful <= 4.4.58 - Admin+ Stored Cross-Site Scripting
medium
The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.5
- Affected:
- up to 4.4.59
- Fixed in:
- 4.4.59
- Disclosed:
- Oct 18, 2021
CVE-2021-24841 on NVD →
Helpful [helpful] < 4.5.15 (closed)
unknown
The plugin allowed users to vote more than once, which could allow attackers to increase votes drastically on some posts
- Affected:
- up to 4.5.15
- Fixed in:
- 4.5.15
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database