Log File Poisoning in Site Checkup Debug AI Troubleshooting Plugin for WordPress
CVE-2025-11627

6.5MEDIUM

What is CVE-2025-11627?

The Site Checkup Debug AI Troubleshooting plugin for WordPress is susceptible to log file poisoning, impacting all versions up to and including 1.47. This vulnerability allows unauthorized attackers to inject arbitrary content into the system's log files. Such exploitation can lead to denial of service due to disk space exhaustion, compromising the performance and stability of affected WordPress sites.

Affected Version(s)

Site Checkup Debug AI Troubleshooting with Wizard and Tips for Each Issue * <= 1.47

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-11627 : Log File Poisoning in Site Checkup Debug AI Troubleshooting Plugin for WordPress