The WP Activity Log Premium plugin for WordPress is vulnerable to something called Cross-Site Request Forgery in versions up to 4.5.0. This means that someone who is unauthenticated (not logged in) may be able to make changes to the plugin’s settings without being noticed, if they can get a site administrator to click on something like a link. This is because the plugin does not have the right protection (called nonce validation) on a function called ajax_switch_db.