Stored Cross-Site Scripting Vulnerability in WP Activity Log Plugin for WordPress
CVE-2025-0924
7.2HIGH
What is CVE-2025-0924?
The WP Activity Log plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate input sanitization and output escaping in the 'message' parameter. This vulnerability affects all versions up to and including 5.2.2. Attackers can exploit this flaw by injecting malicious web scripts, which will execute when a user accesses the compromised page, potentially leading to unauthorized actions and data breaches.
Affected Version(s)
WP Activity Log 0 <= 5.2.2