Unauthenticated Cross Site Request Forgery in WP Activity Log by WordPress
CVE-2026-65512
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-65512?
The WP Activity Log plugin for WordPress versions up to 5.6.4 is susceptible to an unauthenticated Cross Site Request Forgery (CSRF) vulnerability. This flaw allows attackers to trick users into executing unwanted actions on their behalf without proper authentication, potentially compromising site security. It is essential for administrators to update to a patched version to mitigate any risks associated with this vulnerability.
Affected Version(s)
WP Activity Log 0 <= 5.6.4
WP Activity Log Premium 0 <= 5.6.4