The Helpful WordPress plugin before 4.5.26 puts the exported logs and feedbacks in a publicly accessible location and guessable names, which could allow attackers to download them and retrieve sensitive information such as IP, Names and Email Address depending on the plugin's settings
- https://wpscan.com/vulnerability/468d5fc7-04c6-4354-b134-85ebb25b37ae
- https://github.com/20142995/nuclei-templates