N/A
2026-02-11< 1.2.9
Activity Log for WordPress <= 1.2.8 - Missing Authorization to Sensitive Information Exposure via Log File
Minimum safe version
1.2.9
Update to 1.2.9 or later to address 8 fixable vulnerabilities
Activity Log for WordPress <= 1.2.8 - Missing Authorization to Sensitive Information Exposure via Log File
CVE-2026-24987
WordPress Plugin "Activity Log WinterLock" vulnerable to cross-site request forgery
WordPress WP System Log Plugin <= 1.2.4 is vulnerable to Cross Site Request Forgery (CSRF)
WordPress WP System Log Plugin < 1.2.2 is vulnerable to Cross Site Scripting (XSS)
WordPress WP System Log plugin <= 1.0.22 - Sensitive Information Disclosure vulnerability
WordPress WP System Log plugin <= 1.0.22 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability
CVE-2021-24756