Description
The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-58055 | The Debug Log Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.1. This is due to missing or incorrect nonce validation on the clear_log() function. This makes it possible for unauthenticated attackers to clear the debug log via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. |
References
History
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Debug Log Manager <= 2.2.0 - Cross-Site Request Forgery | |
| References |
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:03:06.220Z
Reserved: 2023-10-25T22:04:46.513Z
Link: CVE-2023-5772
No data.
Status : Modified
Published: 2023-11-30T04:15:08.090
Modified: 2026-04-08T18:18:33.320
Link: CVE-2023-5772
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD