CVE-2021-24761

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/02/2022
Last modified:
27/10/2022

Description

The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bestwebsoft:error_log_viewer:*:*:*:*:*:wordpress:*:* 1.1.2 (excluding)