Unauthorized Data Access in Activity Log for WordPress Plugin
CVE-2026-1671
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 February 2026
What is CVE-2026-1671?
The Activity Log plugin for WordPress has a vulnerability that allows authenticated attackers, including users with Subscriber-level access and above, to access sensitive information due to a missing capability check in the winter_activity_log_action() function. This weakness exposes certain log files that may contain confidential details, such as administrator passwords, posing a significant security risk to affected WordPress installations.
Affected Version(s)
Activity Log for WordPress 0 <= 1.2.8