Unauthorized Data Modification in WP Activity Log Premium Plugin for WordPress
CVE-2023-2284
4.3MEDIUM
What is CVE-2023-2284?
The WP Activity Log Premium plugin for WordPress contains a vulnerability that allows authenticated users with subscriber level access or higher to modify plugin settings due to a lack of proper capability checks in the ajax_switch_db function. This security flaw could potentially allow attackers to alter important configurations, posing risks to site integrity and user data.
Affected Version(s)
WP Activity Log Premium * <= 4.5.0