WP Activity Log

WP Activity Log is a WordPress plugin that allows users to keep an activity log of everything that happens on their WordPress sites and multisite networks. It helps improve user accountability, ease troubleshooting, and better manage and organize WordPress sites and users. The plugin has been featured on popular WordPress websites such as WPBeginner, GoDaddy, and Kinsta. WP Activity Log is free to use and offers additional features such as reports, email notifications, SMS alerts, and search and filters.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in WP Activity Log 5.2.1

    Fixed

    The WP Activity Log tool for WordPress is at risk for a type of cyber attack called Stored Cross-Site Scripting. This can happen because the plugin does not properly clean and protect information tha...

    Read More
  • Input validation vulnerability in WP Activity Log 4.6.1

    Fixed

    The WP Activity Log plugin for WordPress has a security issue that allows malicious code to be injected into pages. This can be done by attackers who are not logged in, and the code will run whenever...

    Read More
  • Input validation vulnerability in Freemius SDK 2.5.9 (1072 components affected)

    Fixed

    The Freemius SDK for WordPress is vulnerable to an attack known as Reflected Cross-Site Scripting. This attack is possible because of insufficient security measures in versions of the Freemius SDK up ...

    Read More
  • Access violation vulnerability in WP Activity Log 4.5.0

    Fixed

    The WP Activity Log plugin for WordPress is not secure in versions up to and including 4.5.0. If an attacker has an account on the site, even with the lowest level of access, they could gain access t...

    Read More
  • Input validation vulnerability in WP Activity Log 4.1.5

    Fixed

    The WP Activity Log plugin for WordPress is vulnerable to a type of attack called SQL Injection. This type of attack can be used to extract sensitive information from the WordPress database. This vul...

    Read More
  • Input validation vulnerability in WP Activity Log 4.5.0

    Fixed

    The WP Activity Log for WordPress is vulnerable to an attack known as Cross-Site Request Forgery. This means that if someone is able to trick a site administrator into clicking on a link, they can ca...

    Read More
  • Input validation vulnerability in WP Activity Log 2.4.3

    Fixed

    The WordPress Activity Log plugin, up to and including version 2.4.3, is vulnerable to a type of malicious attack called Reflected Cross-Site Scripting. This attack is possible if someone can success...

    Read More
  • Access violation vulnerability in WP Activity Log 4.0.2

    Fixed

    The WP Activity Log plugin for WordPress has a security vulnerability that could allow unauthenticated attackers to access configuration options. This is because the plugin's setup_page function does...

    Read More
  • Information leakage vulnerability in WP Activity Log 3.1.1

    Fixed

    A security issue was found in the WP Security Audit Log plugin 3.1.1

    Read More
  • Input validation vulnerability in WP Activity Log 1.2.5

    Fixed

    A security vulnerability was discovered in a plugin for WordPress websites called WP Security Audit Log. This vulnerability allowed people outside the website to take control of the website without th...

    Read More
  • Access violation vulnerability in Freemius SDK (134 components affected)

    Fixed

    The Freemius SDK is a plugin used in WordPress websites. A security vulnerability was discovered in versions up to 2.2.3 which could allow users with subscriber-level permissions to change settings an...

    Read More
  • Access violation vulnerability in Freemius SDK (620 components affected)

    Fixed

    Freemius, a software development kit used by hundreds of WordPress plugin and theme developers, had a security vulnerability in its older versions (up to and including 2.4.2). This vulnerability could...

    Read More