plugin

Error Log Viewer Vulnerabilities

12 known security issues reported for the Error Log Viewer WordPress plugin. Most recent disclosed Oct 10, 2025.

1 high 4 medium

Running Error Log Viewer on your site? Check whether your installed version is affected.

Scan your site free

Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read

medium

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwr_get_file function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the serv...

CVSS:
4.9
Affected:
up to 1.1.6
Fixed in:
1.1.7
Disclosed:
Oct 10, 2025

CVE-2025-9950 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.3

unknown

[en] The Error Log Viewer by BestWebSoft WordPress plugin before 1.1.3 is affected by a Directory Listing issue, allowing users to read and download PHP logs without authorization

Affected:
up to 1.1.3
Fixed in:
1.1.3
Disclosed:
Mar 18, 2024

CVE-2023-6821 on NVD →

Error Log Viewer <= 1.1.2 - Sensitive Information Exposure

medium

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.2 via the plugin's log files. This makes it possible for unauthenticated attackers to extract sensitive data including file paths and other information stored within those l...

CVSS:
5.3
Affected:
up to 1.1.2
Fixed in:
1.1.3
Disclosed:
Feb 20, 2024

CVE-2023-6821 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.2

unknown

[en] The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Mar 14, 2022

CVE-2021-24966 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.2

unknown

[en] The Error Log Viewer WordPress plugin before 1.1.2 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

Affected:
up to 1.1.2
Fixed in:
1.1.2
Disclosed:
Feb 1, 2022

CVE-2021-24761 on NVD →

Error Log Viewer by BestWebSoft <= 1.1.1 - Cross-Site Request Forgery

high

The Error Log Viewer WordPress plugin through 1.1.1 does not perform nonce check when deleting a log file and does not have path traversal prevention, which could allow attackers to make a logged in admin delete arbitrary text files on the web server.

CVSS:
8.8
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Dec 29, 2021

CVE-2021-24761 on NVD →

Error Log Viewer <= 1.1.1 - Arbitrary File Deletion

medium

The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder

CVSS:
5.5
Affected:
up to 1.1.1
Fixed in:
1.1.2
Disclosed:
Nov 10, 2021

CVE-2021-24966 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6

unknown

[en] The error-log-viewer plugin before 1.0.6 for WordPress has multiple XSS issues.

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Aug 21, 2019

CVE-2017-18562 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6

unknown

[en] Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,...

Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
May 22, 2017

CVE-2017-2171 on NVD →

Error Log Viewer by BestWebSoft < 1.0.6 - Reflected Cross-Site Scripting

medium

The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, 1.0.6 due to insufficient input sanitization and output escaping on the 'category' parameter. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a...

CVSS:
6.1
Affected:
up to 1.0.6
Fixed in:
1.0.6
Disclosed:
Apr 17, 2017

CVE-2017-18562 on NVD →

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.0.6

unknown
Affected:
up to 1.0.6
Fixed in:
1.0.6

Error Log Viewer by BestWebSoft [error-log-viewer] < 1.1.7

unknown
Affected:
up to 1.1.7
Fixed in:
1.1.7

CVE-2025-9950 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database