CVE-2026-84759
largeUnauthenticated CSRF in WordPress Activity Log plugin <= 2.13.1
CVE-2026-84759 is a Cross-Site Request Forgery (CSRF, CWE-352) flaw in the Activity Log plugin for WordPress affecting all versions up to and including 2.13.1. An unauthenticated attacker can craft a malicious link or page that, when visited by a logged-in user with sufficient privileges (typically a site administrator), causes the victim's browser to submit unintended state-changing requests to the affected WordPress site without CSRF nonce protection. Successful exploitation could let the attacker modify site or plugin state in the context of the victim user, with the CVSS 7.1 (high) score reflecting low confidentiality, integrity and availability impact and a changed scope. Any WordPress site running Activity Log version 2.13.1 or older is affected. There is currently no public proof-of-concept, the EPSS probability is 0.1% (1st percentile), the flaw is not in CISA KEV, and no exploitation in the wild is known.
What to do: Update the Activity Log plugin to the latest release, i.e. any version above 2.13.1, and verify the installed version under the WordPress plugins page. Until updated, exercise caution with untrusted links while logged in to WordPress as an administrator, since CSRF requires the victim to interact with attacker-controlled content. No exploitation has been reported, so patching promptly ahead of any public PoC is the primary mitigation.
| Activity Log Team Activity Log (WordPress plugin) | <= 2.13.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.