CVE-2025-67561
Description
Missing Authorization vulnerability in Oleksandr Lysyi Debug Log Viewer debug-log-viewer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Debug Log Viewer: from n/a through <= 2.0.3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
The WordPress Debug Log Viewer plugin <=2.0.3 has a missing authorization vulnerability that could allow unauthenticated access to debug logs.
The Debug Log Viewer plugin for WordPress suffers from a missing authorization vulnerability (broken access control). The plugin fails to properly verify permissions before exposing debug logs, allowing unauthorized access. This issue affects versions up to and including 2.0.3 [1].
An unauthenticated attacker can exploit this flaw by directly requesting the debug log functionality, bypassing access controls. The vulnerability is known to be used in mass-exploit campaigns targeting thousands of websites, regardless of size or traffic [1]. No special privileges or network position are required beyond network access to the WordPress site.
Successful exploitation exposes sensitive debug log information, which may include error messages, file paths, database queries, and potentially credentials. This information can aid attackers in further compromising the site. The CVSS score of 5.4 indicates medium severity, but the ease of exploitation elevates the risk in practice [1].
The vendor has released version 2.0.4 to address this issue. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. If updating is not possible, consult a hosting provider or web developer for assistance [1].
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=2.0.3
- Range: <=2.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.