ZeroHour

CVE-2026-84759

large

Unauthenticated CSRF in WordPress Activity Log plugin <= 2.13.1

CVSS 3.1
7.1 high
EPSS
<1%p1
Published
()
Modified
AI analysis

CVE-2026-84759 is a Cross-Site Request Forgery (CSRF, CWE-352) flaw in the Activity Log plugin for WordPress affecting all versions up to and including 2.13.1. An unauthenticated attacker can craft a malicious link or page that, when visited by a logged-in user with sufficient privileges (typically a site administrator), causes the victim's browser to submit unintended state-changing requests to the affected WordPress site without CSRF nonce protection. Successful exploitation could let the attacker modify site or plugin state in the context of the victim user, with the CVSS 7.1 (high) score reflecting low confidentiality, integrity and availability impact and a changed scope. Any WordPress site running Activity Log version 2.13.1 or older is affected. There is currently no public proof-of-concept, the EPSS probability is 0.1% (1st percentile), the flaw is not in CISA KEV, and no exploitation in the wild is known.

What to do: Update the Activity Log plugin to the latest release, i.e. any version above 2.13.1, and verify the installed version under the WordPress plugins page. Until updated, exercise caution with untrusted links while logged in to WordPress as an administrator, since CSRF requires the victim to interact with attacker-controlled content. No exploitation has been reported, so patching promptly ahead of any public PoC is the primary mitigation.

Affected
Activity Log Team Activity Log (WordPress plugin)<= 2.13.1
Estimated exposure
large≈100,000–200,000 WordPress sites (plugin reports roughly 200k active installs on WordPress.org) — The estimate is based on the Activity Log plugin's WordPress.org active-install count, on the order of hundreds of thousands of sites, though actual exploitation additionally requires a logged-in privileged user to be tricked into…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.

Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.