← WordPress Vulnerabilities
WordPress security by component

coreActivity: Activity Logging for

coreActivity: Activity Logging for is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 08, 2025; the highest published CVSS base score is 6.5.

Plugin slug: coreactivity-activity-logging-for-wordpress

CVE-2025-3436: coreActivity: Activity Logging for: SQL injection

coreActivity: Activity Logging for is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedApr 08, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for coreactivity-activity-logging-for-wordpress
Safe version
Apr 08, 2025 CVE-2025-3436
coreActivity: Activity Logging for: SQL injection
coreActivity: Activity Logging for is affected by SQL injection. Exploitation requires an authenticated subscriber account. A successful request can alter database queries and expose or modify WordPress data. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending