Input validation vulnerability in Activity Log 2.6.1

The Activity Log plugin for WordPress versions 2.3.5 – 2.6.1 is vulnerable to a security issue known as SQL Injection. SQL Injection is when an attacker can add additional malicious code to an existing query, which can be used to gain access to sensitive information from the database. This problem is caused by the plugin not properly securing the user-supplied parameters, and not preparing the existing SQL query correctly.

Detected in:

Activity Log fixed vulnerable versions: >= 2.3.5 <= 2.6.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.