Cross-site Scripting Vulnerability in Melapress WP Activity Log by WordPress
CVE-2026-25331
6.5MEDIUM
What is CVE-2026-25331?
The vulnerability in Melapress WP Activity Log allows for improper neutralization of input during web page generation, leading to a DOM-based Cross-site Scripting (XSS) issue. This exposure makes the plugin susceptible to injecting malicious scripts into web pages viewed by users, potentially compromising sensitive user data and application integrity. Affected versions of the WP Activity Log plugin include all versions up to and including 5.5.4, emphasizing the need for prompt updates and security measures.
Affected Version(s)
WP Activity Log 0 <= 5.5.4