The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published: 2023-09-04T11:26:56.095Z
Updated: 2025-04-23T16:18:24.845Z
Reserved: 2023-08-09T08:21:12.900Z
Link: CVE-2023-4269

Updated: 2024-08-02T07:24:04.061Z

Status : Modified
Published: 2023-09-04T12:15:10.470
Modified: 2025-04-23T17:16:42.410
Link: CVE-2023-4269

No data.