Developer Loggers for Simple History <= 0.5 - Authenticated (Admin+) Local File Inclusion
mediumThe Developer Loggers for Simple History plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.5 via the enabled_loggers parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary .php files on t...
- CVSS:
- 6.6
- Affected:
- up to 0.5
- Fixed in:
- 0.5.1
- Disclosed:
- Sep 16, 2025