{"error":0,"message":null,"data":{"name":"Activity Log \u2013 Monitor User and Agent Changes","plugin":"aryo-activity-log","link":"https:\/\/wordpress.org\/plugins\/aryo-activity-log\/","latest":"1788764880","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"cefdfb3b80163fd5450726cbf20af5620e3cd097335da09b1730626cf705f5aa","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10891","name":"CVE-2016-10891","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10891","description":"[en] The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.","date":"2019-08-21"},{"id":"6481f9f6-63a6-4cc5-b608-dc7018ade4f6","name":"Activity Log &lt;= 2.3.2 - Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/6481f9f6-63a6-4cc5-b608-dc7018ade4f6","description":"The Activity Log WordPress plugin was affected by a Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"e75a059ff954f018659ad8b02e0993b732e3fb76","name":"Activity Log < 2.3.3 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-233-cross-site-scripting","description":"The aryo-activity-log plugin before 2.3.3 for WordPress has XSS in the search_data parameter in the aryo-activity-log\/classes\/class-aal-activity-log-list-table.php file.","date":"2016-08-03"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"07bbb47cf257cb448fcaf24a46a44dd12353e2447699164a02371e6558dd12a8","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2016-10890","name":"CVE-2016-10890","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2016-10890","description":"[en] The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.","date":"2019-08-21"},{"id":"9d9437bf-3bfa-435f-b2c5-b0f209aa567a","name":"Activity Log &lt;= 2.3.1 - Stored Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/9d9437bf-3bfa-435f-b2c5-b0f209aa567a","description":"The Activity Log WordPress plugin was affected by a Stored Cross-Site Scripting (XSS) security vulnerability.","date":null},{"id":"ec7198a08a3acfbaacc01f9d93f8d4d7126d4ef2","name":"Activity Log <= 2.3.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-232-reflected-cross-site-scripting","description":"The Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2016-08-03"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"af68022fef13c59bbb7cccfb08184f3a3856ba796efef4ab984061cc5857f2cb","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2018-8729","name":"CVE-2018-8729","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2018-8729","description":"[en] Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.","date":"2018-03-15"},{"id":"7e18d478d5c9e8f38cde7f377e0908104aabe3a2","name":"WordPress Activity Log plugin <=2.4.0 - Multiple Cross-Site Scripting (XSS) vulnerabilities","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-4-0-multiple-cross-site-scripting-xss-vulnerabilities","description":"Multiple Cross-Site Scripting (XSS) vulnerabilities found in WordPress Activity Log plugin versions <=2.4.0","date":"2018-03-28"},{"id":"80f05b96-4e3e-4376-a961-4d1af63e1be9","name":"Activity Log &lt;= 2.4.0 - Multiple Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/80f05b96-4e3e-4376-a961-4d1af63e1be9","description":"The Activity Log WordPress plugin was affected by a Multiple Cross-Site Scripting (XSS)  security vulnerability.","date":null},{"id":"201e68edfaf41c7920063211cbde779a3e8e4d65","name":"Activity Log <= 2.4.0 - Multiple Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-240-multiple-cross-site-scripting","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.","date":"2018-03-08"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c4bfef39d94f3a05d3b226c7c8034b9fef4f9cf9a79ba24229b8e93c25faaed6","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"903946c47039192efc7a22a2f31ba81a8574ec43","name":"WordPress Activity Log plugin <= 2.6.1 - Authenticated SQL Injection (SQLi) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/aryo-activity-log\/vulnerability\/wordpress-activity-log-plugin-2-6-1-authenticated-sql-injection-sqli-vulnerability","description":"Authenticated SQL Injection (SQLi) vulnerability discovered by Synacktiv in WordPress Activity Log plugin (versions <= 2.6.1).","date":"2021-05-03"}],"impact":[]},{"uuid":"9bb451927019897bf8714c3d94a8973b450236d074a33018a019305c93d2fb71","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bc45da79d6c6af191323d0791fb85140c9b4ba05","name":"WordPress Activity Log Plugin <= 2.2.12 - Authenticated Information Disclosure Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-2-12-authenticated-information-disclosure-vulnerability","description":"WordPress Activity Log Plugin  Authenticated Information Disclosure Vulnerability is due to the AJAX accessible function ajax_aal_get_properties(), in the file \/classes\/class-aal-settings.php, not having a check to make sure that the request is coming from a user and he should be able to access to it (normally that would only be Administrator level users):\nUpdate the plugin.","date":"2017-07-05"}],"impact":[]},{"uuid":"53e63f8967d5b573b300cc1fa9c0871ef7b68b2d720d9cd09abe44880334bf97","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"edfab76c8f51586c3c6367db03d1738f7e582b95","name":"WordPress Activity Log Plugin <= 2.3.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-3-2-cross-site-scripting","description":"Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-08-03"}],"impact":[]},{"uuid":"fa46a2389618a5e89984d19c83b1dbdc0dea61681fe7880092c871b3c2104f9c","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"112caad471b905ba9e3cfe6519b4eab97f9a424d","name":"WordPress Activity Log Plugin <= 2.3.2 - Cross Site Scripting","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-3-2-cross-site-scripting-1","description":"This plugin is prone to a cross site scripting vulnerability in \"page\" parameter. It allows attackers to inject arbitrary JavaScript or HTML code.\nUpdate the plugin.","date":"2016-08-03"}],"impact":[]},{"uuid":"15b14a58304284e411fa8d4360fe13682aa52f43d6a195315b620966f4e3201d","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"bd5ab2e6b4f54c0545a48152ea3acb9191df7eee","name":"WordPress Activity Log Plugin 2.3.1 - Persistent XSS","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-3-1-persistent-xss","description":"Because of this vulnerability, an attacker can inject malicious JavaScript code in to the application.\nUpgrade the WordPress plugin to the newer stable and safe version.","date":"2016-07-11"}],"impact":[]},{"uuid":"48f70377d9053d30ebc44d8b1f15c7d4bb31664639a217bf0dd204045c2f1a9d","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5bd308fe28cff3603486a042e41952d4fc3eb4c7","name":"WordPress Activity Log Plugin <= 2.0.3  - Full Path Disclosure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/activity-log\/vulnerability\/wordpress-activity-log-plugin-2-0-3-full-path-disclosure","description":"This plugin is prone to a full path disclosure vulnerability.\nUpdate the plugin.","date":"2014-08-01"}],"impact":[]},{"uuid":"ec25bc6161912c8c41335bc12ad81970a88c42748440c51a0d0f37aadf16ebe0","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.8.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-27858","name":"CVE-2022-27858","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-27858","description":"[en] CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.","date":"2022-11-08"},{"id":"5c6eb9180679d6f92cef7c8b300428fa3279fceb","name":"WordPress Activity Log plugin <= 2.8.3 - CSV Injection vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/aryo-activity-log\/vulnerability\/wordpress-activity-log-plugin-2-8-3-csv-injection-vulnerability","description":"CSV Injection vulnerability discovered by Universe (Patchstack Alliance) in WordPress Activity Log plugin (versions <= 2.8.3)\nUpdate the WordPress Activity Log plugin to the latest available version (at least 2.8.4).","date":"2022-09-26"},{"id":"c3267010fe21c4ad075f37e07e0161f852e670b1","name":"Activity Log <= 2.8.3 - CSV Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-283-csv-injection","description":"The Activity Log plugins for WordPress is vulnerable to CSV Injection in versions up to, and including, 2.8.3. This allows unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.","date":"2022-09-26"},{"id":"d43c4ff8-fec5-4202-b534-afdded91ed65","name":"Activity Log &lt; 2.8.4 - CSV Injection","link":"https:\/\/wpscan.com\/vulnerability\/d43c4ff8-fec5-4202-b534-afdded91ed65","description":"The plugin does not validate data when output it back in a CSV file, which could lead to CSV injection","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"n","i":"h","a":"n","score":"7.4","severity":"h","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:N\/I:H\/A:N","score":"7.4","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"5.9"},"cwe":[{"cwe":"CWE-1236","name":"Improper Neutralization of Formula Elements in a CSV File","description":"The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f93677c75f1b485077ac075b9e0d39de5fe0298777a97fec66ee5ea146a40731","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.7.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.7.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"279972d3-6847-4d84-8532-01ff96f0aacc","name":"Activity Log &lt; 2.7.0 - Authenticated SQL Injection","link":"https:\/\/wpscan.com\/vulnerability\/279972d3-6847-4d84-8532-01ff96f0aacc","description":"The plugin was vulnerable to SQL Injection in the order column of the past events table.","date":null}],"impact":[]},{"uuid":"b8817a7d259f869628b22e92033c6aa56944210c234d0ec91db5a70815d5fb20","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"58cfe6fc-f1e5-4a87-84b3-7b190a140c4d","name":"Activity Log &lt;= 2.3.2 - Cross-Site Scripting (XSS) in &#039;page&#039;","link":"https:\/\/wpscan.com\/vulnerability\/58cfe6fc-f1e5-4a87-84b3-7b190a140c4d","description":"The Activity Log WordPress plugin was affected by a Cross-Site Scripting (XSS) in &#039;page&#039; security vulnerability.","date":null}],"impact":[]},{"uuid":"60d80f524b699042e20da08ec56eacccc0effb632ada1b82c1c351eef196358d","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"ee3e31f5-dd38-4723-8469-f3f2ddb34a65","name":"Activity Log - Full Path Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/ee3e31f5-dd38-4723-8469-f3f2ddb34a65","description":"The Activity Log WordPress plugin was affected by a Full Path Disclosure security vulnerability.","date":null}],"impact":[]},{"uuid":"f7caca4b542ccea6b104874242f761f0eefaf72dab0f3bbec6cefba91fa1286e","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] >= 2.3.5 - <= 2.6.1","description":null,"operator":{"min_version":"2.3.5","min_operator":"ge","max_version":"2.6.1","max_operator":"le","unfixed":"0","closed":"0"},"source":[{"id":"45064bb80a0db69a70d1efbbdd7e352e4963e2c3","name":"Activity Log 2.3.5 - 2.6.1 - SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-235-261-sql-injection","description":"The Activity Log plugin for WordPress is vulnerable to SQL Injection via the \u2018orderby\u2019 parameter in versions 2.3.5 - 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2021-05-03"}],"impact":[]},{"uuid":"7bf68c86ad6750d79ea4bc6557d9232c9aa7a1a45f61237301be666df758a56d","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"0dd542229d2dbc3ef46d879a20a82e5cff8ae0c5","name":"Activity Log <=  2.3.2 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-232-reflected-cross-site-scripting-2","description":"The Activity Log Plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the \u2018 page\u2019 parameter in versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2016-07-29"}],"impact":[]},{"uuid":"a8cd98df9bd2d7a2be00143aa71569199523530df4974424c1e9bdac88e4cf97","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"dfaa165c9205d1813725c0d7ca20de0297eed091","name":"Activity Log Plugin < 2.0.4 - Fulle Path Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-plugin-204-fulle-path-disclosure","description":"The Activity Log plugin for WordPress is vulnerable to Sensitive Data Exposure in versions up to, and including, 2.0.3 via direct calls to the ~\/class-aal-integration-woocommerce.php file. This can allow unauthenticated attackers to extract sensitive data including the full path of the WordPress installation.","date":"2014-02-27"}],"impact":[]},{"uuid":"5562f417a75ad799222df6ed3ebffe72fe77f722af48b32c726f9a2d1641a5e1","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.8.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-4281","name":"CVE-2023-4281","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-4281","description":"[en] This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.","date":"2023-09-25"},{"id":"5ef7872fc464f5386bff3273bc2f4f504c783500","name":"Activity Log <= 2.8.7 - IP Address Spoofing","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-287-ip-address-spoofing","description":"The Activity Log plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.8.7. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging. Unauthenticated attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged instead of the users true IP address.","date":"2023-09-01"},{"id":"949cea87579c30787e2c7224760c9ae5853315da","name":"WordPress  Activity Log Plugin  < 2.8.8 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/aryo-activity-log\/vulnerability\/wordpress-activity-log-plugin-2-8-8-ip-spoofing-vulnerability","description":"Update the WordPress Activity Log plugin to the latest available version (at least 2.8.8).\nBartlomiej Marek and Tomasz Swiadek discovered and reported this Bypass Vulnerability vulnerability in WordPress Activity Log Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has been fixed in version 2.8.8.","date":"2023-09-06"},{"id":"f5ea6c8a-6b07-4263-a1be-dd033f078d49","name":"Activity Log &lt; 2.8.8 - IP Spoofing","link":"https:\/\/wpscan.com\/vulnerability\/f5ea6c8a-6b07-4263-a1be-dd033f078d49","description":"This plugin retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-290","name":"Authentication Bypass by Spoofing","description":"This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"9ef474a52bc3e9982046ab9db7db66bbc8bafb4ff89d1188944c0a341268dffc","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.11.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.11.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10788","name":"CVE-2024-10788","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10788","description":"[en] The Activity Log \u2013 Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.","date":"2024-11-21"},{"id":"d44c48856cfe82f29b1858d98288394e82092571","name":"Activity Log \u2013 Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scripting via Event Context","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-monitor-record-user-changes-2111-unauthenticated-stored-cross-site-scripting-via-event-context","description":"The Activity Log \u2013 Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an administrative user accesses an injected page.","date":"2024-11-20"},{"id":"a30636f42b31068d3d82c3ac10a6cac23ab7d4a6","name":"WordPress Activity Log Plugin <= 2.11.1 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/aryo-activity-log\/vulnerability\/wordpress-activity-log-monitor-record-user-changes-plugin-2-11-1-unauthenticated-stored-cross-site-scripting-via-event-context-vulnerability","description":"<p>WordPress Activity Log Plugin <= 2.11.1 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: Activity Log<\/p><p>Link: https:\/\/wordpress.org\/plugins\/aryo-activity-log\/#developers<\/p><p>Affected Version <= 2.11.1<\/p><p>Fixed in version 2.11.2 <\/p>","date":"2024-11-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"7.2","severity":"h","exploitable":"3.9","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"7.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.9","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"2adfc96756f49fc2f9ff568bf63e26a01fb9c86b2289d28ea6b32cb766b2f9f1","name":"Activity Log \u2013 Monitor User and Agent Changes [aryo-activity-log] < 2.14.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.14.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-84759","name":"CVE-2026-84759","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-84759","description":"[en] Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.","date":"2026-09-02"},{"id":"d4647e6e5a650166947581e934c476786f2d660b","name":"WordPress Activity Log Plugin <= 2.13.1 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/aryo-activity-log\/vulnerability\/wordpress-activity-log-plugin-2-13-1-cross-site-request-forgery-csrf-vulnerability","description":"<p>WordPress Activity Log Plugin <= 2.13.1 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: Activity Log<\/p><p>Fixed in version 2.14.0 <\/p><p>Affected Version <= 2.13.1<\/p><p>CVE: CVE-2026-84759<\/p>","date":"2026-09-02"},{"id":"f1d266b64b3c2ca52d0ef8193aa67984956cb4d9","name":"Activity Log \u2013 Monitor User and Agent Changes <= 2.13.1 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/aryo-activity-log\/activity-log-monitor-user-and-agent-changes-2131-cross-site-request-forgery","description":"The Activity Log \u2013 Monitor User and Agent Changes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.13.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-11-20"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789024778"}