PT-2022-9457 · WordPress · Error Log Viewer

Apple502J

·

Published

2022-02-01

·

Updated

2022-10-27

·

CVE-2021-24761

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Error Log Viewer WordPress plugin versions prior to 1.1.2
Description The issue concerns a lack of nonce check when deleting a log file and the absence of path traversal prevention. This could allow attackers to make a logged-in admin delete arbitrary text files on the web server.
Recommendations For Error Log Viewer WordPress plugin versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the log file deletion functionality to minimize the risk of exploitation.

Exploit

Fix

Path traversal

CSRF

Weakness Enumeration

Related Identifiers

CVE-2021-24761

Affected Products

Error Log Viewer