ZeroHour

CVE-2023-4269

PoC
CVSS 3.1
4.3 medium
EPSS
<1%p43
Published
()
Modified
Description

The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

Vendors
solwininfotech
Products
user activity log
Ecosystems
WordPress
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.