SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-24966

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

MEDIUM 4.9EPSS 5.19%

Does this matter?

Lower severity and a low EPSS score (5.19%). Track it; it rarely justifies an emergency change on its own.

Description

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

CVSS 3.1
4.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS
5.19% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-73
Affected
bestwebsoft/error log viewer
Source
contact@wpscan.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.