WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.
Metrics
Affected Vendors & Products
References
History
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface. | |
| Title | WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-11T15:58:55.972Z
Reserved: 2026-02-11T14:34:36.850Z
Link: CVE-2019-25315
Updated: 2026-02-11T15:58:53.191Z
Status : Awaiting Analysis
Published: 2026-02-11T15:16:10.440
Modified: 2026-02-11T15:27:26.370
Link: CVE-2019-25315
No data.
OpenCVE Enrichment
No data.