Uncontrolled Resource Consumption Vulnerability in UserLog Plugin by WordPress
CVE-2025-55128

6.5MEDIUM

Key Information:

Vendor

Revive

Vendor
CVE Published:
20 November 2025

What is CVE-2025-55128?

A vulnerability has been identified in the UserLog plugin for WordPress, allowing an attacker with admin access to request an excessive number of items per page via the 'userlog-index.php' file. This could lead to a denial of service, significantly impacting the performance and availability of the application. It is crucial for administrators to review permissions and apply necessary restrictions to mitigate this risk.

Affected Version(s)

Revive Adserver 6 <= 6.0.2

Revive Adserver 6.0.3

References

CVSS V3.0

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55128 : Uncontrolled Resource Consumption Vulnerability in UserLog Plugin by WordPress