Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical0
High0
Medium4
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2025-10-14

CVE-2025-9950 - Error Log Viewer Plugin

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.

PLUGIN Error Log Viewer

CVE-2025-9950

MEDIUM CVSS 4.9 2025-10-11
Threat Entry Updated 2025-03-27

CVE-2023-6821 - Error Log Viewer Plugin

The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

PLUGIN Error Log Viewer

CVE-2023-6821

MEDIUM CVSS 6.5 2024-03-18
Threat Entry Updated 2024-11-21

CVE-2021-24966 - Error Log Viewer Plugin

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

PLUGIN Error Log Viewer

CVE-2021-24966

MEDIUM CVSS 4.9 2022-03-14
Threat Entry Updated 2024-11-21

CVE-2021-24761 - Error Log Viewer Plugin

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

PLUGIN Error Log Viewer

CVE-2021-24761

MEDIUM CVSS 6.5 2022-02-01
Scroll to top