CVE-2025-13471
User Activity Log
CVE-2025-11877
CVE-2024-31356
CVE-2023-4269
CVE-2023-4279
WordPress User Activity Log Plugin <= 1.6.5 is vulnerable to Broken Access Control
User Activity Log <= 1.6.5 - Unauthenticated Data Export to Sensitive Information Disclosure
CVE-2023-3435
CVE-2023-2761
User Activity Log <= 1.6.2 - Unauthenticated SQL Injection via username
CVE-2023-37966
User Activity Log <= 1.6.2 - Authenticated(Administrator+) SQL Injection via txtsearch
User Activity Log < 1.4.7 - Reflected Cross-Site Scripting
User Activity Log < 1.4.7 - Reflected Cross Site Scripting via Query String
User Activity Log <= 1.4.6 - Reflected Cross Site Scripting
User Activity Log <= 1.4.6 - Reflected Cross-Site Scripting
WordPress User Activity Log Plugin <= 1.2.3 - Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) Vulnerabilities