WordPress security by component
coreActivity: Activity Logging for
Plugin description
coreActivity: Activity Logging for is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 08, 2025; the highest published CVSS base score is 6.5.
Plugin slug:
coreactivity-activity-logging-for-wordpressLatest vulnerability
CVE-2025-3436: coreActivity: Activity Logging for: SQL injection
coreActivity: Activity Logging for is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Apr 08, 2025 |
CVE-2025-3436
coreActivity: Activity Logging for: SQL injection
coreActivity: Activity Logging for is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|