VulnerabilityModified
CVE-2021-24966
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
MEDIUM 4.9EPSS 5.19%
Does this matter?
Lower severity and a low EPSS score (5.19%). Track it; it rarely justifies an emergency change on its own.
Description
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
- CVSS 3.1
- 4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 5.19% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-73
- Affected
- bestwebsoft/error log viewer
- Source
- contact@wpscan.com
References
- https://wpscan.com/vulnerability/166a4f88-4f0c-4bf4-b624-5e6a02e21fa0Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/166a4f88-4f0c-4bf4-b624-5e6a02e21fa0Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.