๐Ÿ” CVE Alert

CVE-2025-11627

MEDIUM 6.5

Site Checkup AI Troubleshooting with Wizard and Tips for Each Issue <= 1.47 - Unauthenticated Log File Poisoning

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

The Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue plugin for WordPress is vulnerable to log file poisoning in all versions up to, and including, 1.47. This makes it possible for unauthenticated attackers to insert arbitrary content into log files, and potentially cause denial of service via disk space exhaustion.

CWE CWE-117
Vendor sminozzi
Product site checkup debug ai troubleshooting with wizard and tips for each issue
Published Oct 30, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for sminozzi site checkup debug ai troubleshooting with wizard and tips for each issue

Be the first to know when new medium vulnerabilities affecting sminozzi site checkup debug ai troubleshooting with wizard and tips for each issue are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

sminozzi / Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue
0 โ‰ค 1.47

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/50251b17-58d7-4870-b825-a194312fb3e7?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/site-checkup/tags/1.47/includes/catch-errors/class_bill_catch_errors.php#L80 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset/3380169/

Credits

Jonas Benjamin Friedli