Medium 6.5
2025-04-08< 2.7.1
WordPress coreActivity: Activity Logging plugin for WordPress Plugin <= 2.7 is vulnerable to SQL Injection
Minimum safe version
2.7.1
Update to 2.7.1 or later to address 4 fixable vulnerabilities
WordPress coreActivity: Activity Logging plugin for WordPress Plugin <= 2.7 is vulnerable to SQL Injection
CVE-2024-0868
WordPress coreActivity: Activity Logging plugin for WordPress Plugin <= 1.8 is vulnerable to Cross Site Scripting (XSS)
coreActivity <= 1.8 - Unauthenticated Stored Cross-Site Scripting