Cross-Site Scripting Vulnerability in Melapress WP Activity Log
CVE-2026-45435
6.5MEDIUM
What is CVE-2026-45435?
The vulnerability in the Melapress WP Activity Log plugin allows an attacker to exploit improper neutralization of input during web page generation, leading to DOM-based Cross-Site Scripting (XSS). This can permit unauthorized execution of scripts in a user's browser, resulting in potential data theft or site compromise. Affected versions span from the initial release to 5.6.3.
Affected Version(s)
WP Activity Log <= 5.6.3