Melapress

Wp Activity Log

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 23.07.2026 11:19:09
  • Zuletzt bearbeitet 05.08.2026 09:18:15

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.

  • EPSS 0.26%
  • Veröffentlicht 25.06.2026 13:12:37
  • Zuletzt bearbeitet 25.06.2026 15:16:39

Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.

  • EPSS 0.7%
  • Veröffentlicht 17.06.2026 09:51:45
  • Zuletzt bearbeitet 17.06.2026 09:51:45

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

  • EPSS 0.2%
  • Veröffentlicht 25.05.2026 22:28:19
  • Zuletzt bearbeitet 24.07.2026 10:10:00

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS. This issue affects WP Activity Log: from n/a through 5.6.3.

  • EPSS 0.16%
  • Veröffentlicht 19.02.2026 08:26:57
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log wp-security-audit-log allows DOM-Based XSS.This issue affects WP Activity Log: from n/a through <= 5.5.4.

  • EPSS 0.45%
  • Veröffentlicht 27.02.2025 19:15:49
  • Zuletzt bearbeitet 21.05.2025 17:06:08

WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.

  • EPSS 1.35%
  • Veröffentlicht 17.02.2025 05:15:09
  • Zuletzt bearbeitet 23.05.2025 17:41:46

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter in all versions up to, and including, 5.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unaut...

  • EPSS 1.29%
  • Veröffentlicht 15.11.2024 06:15:04
  • Zuletzt bearbeitet 19.11.2024 21:13:22

The WP Activity Log plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the user_id parameter in all versions up to, and including, 5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthe...

  • EPSS 0.88%
  • Veröffentlicht 09.04.2024 19:15:24
  • Zuletzt bearbeitet 08.04.2026 17:18:28

The WP Activity Log Premium plugin for WordPress is vulnerable to SQL Injection via the entry->roles parameter in all versions up to, and including, 4.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation ...

  • EPSS 0.33%
  • Veröffentlicht 29.02.2024 06:15:45
  • Zuletzt bearbeitet 28.04.2026 19:22:41

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows Stored XSS.This issue affects WP Activity Log: from n/a through 4.6.1.