Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager debug-log-manager allows Stored XSS.This issue affects Debug Log Manager: from n/a through <= 2.3.4.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows the improper neutralization of user-supplied data when it is rendered on a web page, leading to stored XSS. An attacker with access to the vulnerable plugin’s input fields can inject malicious scripts that will be persisted in the log store and later executed in the browsers of users who view these logs, potentially compromising user sessions, defacing the site, or stealing credentials. The weakness is a classic input–output vulnerability identified as CWE‑79, which is commonly mitigated by proper output encoding and validation.

Affected Systems

The flaw affects the Bowo Debug Log Manager WordPress plugin, versions up to and including 2.3.4. The vulnerability is present in every installation of the plugin that is at or below this version threshold; any site using the affected plugin is at risk.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity level, while an EPSS score of less than 1% suggests a low current likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve the plugin’s logging interface, where an attacker can submit malicious payloads that are stored and later rendered to users. Although no public exploit has been reported, the stored nature of the XSS makes it a high‑impact risk to any user who accesses the log view.

Generated by OpenCVE AI on April 30, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Debug Log Manager plugin to the latest version (2.3.5 or newer)
  • If an upgrade is unavailable, remove or disable the plugin entirely
  • Apply a content‑security‑policy header and escape all log output to mitigate any residual XSS risk

Generated by OpenCVE AI on April 30, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11705 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS. This issue affects Debug Log Manager: from n/a through 2.3.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS. This issue affects Debug Log Manager: from n/a through 2.3.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager debug-log-manager allows Stored XSS.This issue affects Debug Log Manager: from n/a through <= 2.3.4.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bowo Debug Log Manager allows Stored XSS. This issue affects Debug Log Manager: from n/a through 2.3.4.
Title WordPress Debug Log Manager plugin <= 2.3.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Bowo Debug Log Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:25.316Z

Reserved: 2025-04-09T11:20:35.409Z

Link: CVE-2025-32613

cve-icon Vulnrichment

Updated: 2025-04-17T18:07:44.656Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:46.797

Modified: 2026-04-23T15:29:12.720

Link: CVE-2025-32613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T22:00:08Z

Weaknesses