Lucene search

K
cvelistWPScanCVELIST:CVE-2023-4269
HistorySep 04, 2023 - 11:26 a.m.

CVE-2023-4269 User Activity Log < 1.6.6 - Subscriber+ Log Export

2023-09-0411:26:56
WPScan
www.cve.org
2
wordpress
plugin
authorisation
pii
email addresses

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

23.9%

The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

CNA Affected

[
  {
    "vendor": "Unknown",
    "product": "User Activity Log",
    "versions": [
      {
        "status": "affected",
        "versionType": "custom",
        "version": "0",
        "lessThan": "1.6.6"
      }
    ],
    "defaultStatus": "unaffected",
    "collectionURL": "https://wordpress.org/plugins"
  }
]

AI Score

4.9

Confidence

High

EPSS

0.001

Percentile

23.9%

Related for CVELIST:CVE-2023-4269