The Error Log Viewer WordPress plugin through 1.1.1 does not validate the path of the log file to clear, allowing high privilege users to clear arbitrary files on the web server, including those outside of the blog folder
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-03-14T14:41:06
Updated: 2024-08-03T19:49:14.380Z
Reserved: 2021-01-14T00:00:00
Link: CVE-2021-24966
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-14T15:15:08.760
Modified: 2024-11-21T05:54:06.073
Link: CVE-2021-24966
Redhat
No data.