Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read
medium
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the serv...
- CVSS:
- 4.9
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Oct 10, 2025
CVE-2025-9950 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.3
unknown
[en] The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization
- Affected:
- up to 1.1.3
- Fixed in:
- 1.1.3
- Disclosed:
- Mar 18, 2024
CVE-2023-6821 on NVD →
Error Log Viewer <= 1.1.2 - Sensitive Information Exposure
medium
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.2 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including file paths and other information stored within those l...
- CVSS:
- 5.3
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.3
- Disclosed:
- Feb 20, 2024
CVE-2023-6821 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.2
unknown
[en] The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Mar 14, 2022
CVE-2021-24966 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.2
unknown
[en] The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.
- Affected:
- up to 1.1.2
- Fixed in:
- 1.1.2
- Disclosed:
- Feb 1, 2022
CVE-2021-24761 on NVD →
Error Log Viewer by BestWebSoft <= 1.1.1 - Cross-Site Request Forgery
high
The Error Log Viewer WordPress plugin through 1.1.1 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.
- CVSS:
- 8.8
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Dec 29, 2021
CVE-2021-24761 on NVD →
Error Log Viewer <= 1.1.1 - Arbitrary File Deletion
medium
The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
- CVSS:
- 5.5
- Affected:
- up to 1.1.1
- Fixed in:
- 1.1.2
- Disclosed:
- Nov 10, 2021
CVE-2021-24966 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6
unknown
[en] The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Aug 21, 2019
CVE-2017-18562 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6
unknown
[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- May 22, 2017
CVE-2017-2171 on NVD →
Error Log Viewer by BestWebSoft < 1.0.6 - Reflected Cross-Site Scripting
medium
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, 1.0.6 due to insufficient input sanitization and output escaping on the 'category' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a...
- CVSS:
- 6.1
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
- Disclosed:
- Apr 17, 2017
CVE-2017-18562 on NVD →
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6
unknown
- Affected:
- up to 1.0.6
- Fixed in:
- 1.0.6
Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.7
unknown
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
CVE-2025-9950 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database