Input validation vulnerability in WP Activity Log Premium 4.5.0

The WP Activity Log Premium plugin for WordPress is vulnerable to something called Cross-Site Request Forgery in versions up to 4.5.0. This means that someone who is unauthenticated (not logged in) may be able to make changes to the plugin’s settings without being noticed, if they can get a site administrator to click on something like a link. This is because the plugin does not have the right protection (called nonce validation) on a function called ajax_switch_db.

Detected in:

WP Activity Log Premium fixed vulnerable versions: >= * <= 4.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.