Back

CRITICAL

User Activity Log < 1.6.5 - Unauthenticated SQLi

Published Aug 14, 2023

Description

The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner WPScan
Published Aug 14, 2023
Updated Oct 9, 2024
Reserved Jun 27, 2023

CISA Vulnrichment

Updated Oct 9, 2024

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner WPScan
Published Aug 14, 2023
Updated Oct 9, 2024

GitHub

No data