Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown
CVE-2023-4150
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
The User Activity Tracking and Log WordPress plugin before 4.0.9 does not have proper CSRF checks when managing its license, which could allow attackers to make logged in admins update and deactivate the plugin's license via CSRF attacks
0
Attacker Value
Unknown
CVE-2023-3435
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.
0
Attacker Value
Unknown
CVE-2023-2761
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.
0