Developer Loggers for Simple History

Developer Loggers for Simple History has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 6.6, and the most serious one scores 6.6 out of 10.

The most common weakness is Path Traversal, behind 1 of the records (100%).

The one issue recorded for Developer Loggers for Simple History has a vendor fix available, so running the current release closes it.

All of these findings were reported by Jonas Benjamin Friedli. Developer Loggers for Simple History is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.4.10.

Strategic Overview

Avg CVSSMedium
6.6/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Developer Loggers for Simple History vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.6CVE-2025-10050

Developer Loggers for Simple History <= 0.5 - Authenticated (Admin+) Local File Inclusion

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv0.5.1

Developer Loggers for Simple History

Pär Thernström

Author

Pär Thernström

0.0(0)
0/100
Last Updated
2025-09-15 (1y ago)
Active Installs
400+
Downloads
8,694
Requires WP
4.4+
Requires PHP
0+
Tested up to
WP 6.4.10
Created
2015-12-05 (11y ago)

Bring more loggers to WordPress user history plugin Simple History. That are useful for developers during development of a site or to maintain a live site. Important Please note that this plugin is no longer actively maintained and only receives security fixes. Modern and up to date alternatives For an up to date alternative please see the Debug & Monitor add-on which logs WP REST API requests, sent emails, HTTP API requests, and WP cron jobs. Get more features with Simple History Premium Need advanced WordPress audit logging capabilities? Simple History Premium extends your site monitoring with powerful features: Enhanced WordPress Activity Logging: Advanced Analytics Dashboard – Comprehensive stats and visual activity tracking Custom Event Logging – Add manual entries and notifications to your audit trail Stealth Mode – Control user access with granular permissions Flexible Log Retention – Configure automatic cleanup or keep logs indefinitely Data Export Tools – Export logs in CSV/JSON format for analysis Security Features – IP anonymization and login attempt location tracking » Get Simple History Premium Included loggers and plugins Post to Slack All your events is posted to a Slack channel of your choice, using an incoming webhook. Yes, with this plugin enabled there is no need what so ever to ever leave Slack to see what’s happening on your site or the site of your clients or… well, on any site where you have Simple Histor and this plugin enabled. WP_Mail-logger See all mails sent with wp_mail(), no matter what the recipient address is. changelog 404 logger View page visits that load the 404 template. JavaScript error logger See what JavaScript errors users that visit your site is getting. SystemLog logger Log all messages from Simple History to the syslog on the server. With this logger enabled there is no need to use the beautiful GUI of Simple History ;). HTTP API logger Log all usage of HTTP calls from functions like wp_remote_post() and wp_remote_get(). You can the URL requested, the arguments posted and the full returned result, including server headers. The time for the request to complete is also logged. Great for debugging!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C