Known vulnerabilities in the WP Activity Log plugin
9 security advisories have been published for the WP Activity Log plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- WP Activity Log - Cross-Site Scripting (XSS) (CVE-2026-56005) HIGH
- WP Activity Log - PHP Object Injection (CVE-2026-54806) CRITICAL
- Wp Activity Log - Cross-Site Scripting (XSS) (CVE-2025-0924) HIGH
- Wp Activity Log - Cross-Site Scripting (XSS) (CVE-2024-10793) HIGH
- Wp Activity Log - SQL Injection (CVE-2024-2018) HIGH
- Wp Activity Log - Cross-Site Request Forgery (CSRF) (CVE-2023-2286) MEDIUM
- Wp Activity Log - Cross-Site Request Forgery (CSRF) (CVE-2023-2285) MEDIUM
- Wp Activity Log - Broken Access Control (CVE-2023-2284) MEDIUM
- Wp Activity Log - Broken Access Control (CVE-2023-2261) MEDIUM