The WordPress Activity Log plugin, up to and including version 2.4.3, is vulnerable to a type of malicious attack called Reflected Cross-Site Scripting. This attack is possible if someone can successfully convince a user to click on a link. Once clicked, the link may allow malicious code to be injected into a page, allowing it to execute. It is caused by insufficient input sanitization and output escaping.