← back
CVE-2021-24966CWE-73

Error Log Viewer Plugin <= 1.1.1 - Admin+ Arbitrary File Clearing

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 5.2%
from disclosure to weapon0 days
Published on NVDMar 14
1st PoCFeb 16
exploitation probability
5.2%top 8% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.