WP Server Log Viewer GitHub Repositoryproduct
https://github.com/anttiviljami/wp-server-log-viewer CVE-2019-25315
MEDIUM
WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site Scripting
Record summary
CVE-2019-25315 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
WordPress Server Log Viewer 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unfiltered log file paths. Attackers can add log files with embedded XSS payloads that will execute when viewed in the WordPress admin interface.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WP Server Log ViewerBrowse anttiviljami / WP Server Log Viewer | CVE List | 1.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBWP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site ScriptingExploitDB exploitby striderNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25315 ExploitDB-47419exploit
https://www.exploit-db.com/exploits/47419 VulnCheck Advisory: WP Server Log Viewer 1.0 - 'logfile' Persistent Cross-Site ScriptingThird-party advisory
https://www.vulncheck.com/advisories/wp-server-log-viewer-logfile-persistent-cross-site-scripting