CVE-2025-9950: Error Log Viewer by BestWebSoft <= 1.1.6 - Authenticated (Administrator+) Arbitrary File Read
The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.1.6 via the rrrlgvwrgetfile function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9950?
CVE-2025-9950 is classified as a high severity vulnerability due to its potential for exploitation by authenticated attackers with Administrator access.
How do I fix CVE-2025-9950?
To fix CVE-2025-9950, update the BestWebSoft Error Log Viewer plugin to version 1.1.7 or later.
Who is affected by CVE-2025-9950?
CVE-2025-9950 affects all versions of the BestWebSoft Error Log Viewer plugin up to and including version 1.1.6.
What type of vulnerability is CVE-2025-9950?
CVE-2025-9950 is a directory traversal vulnerability that allows attackers to read arbitrary files on the server.
What access level is required to exploit CVE-2025-9950?
Authenticated users with Administrator-level access can exploit CVE-2025-9950.