Unauthenticated Cross Site Request Forgery in WP Activity Log by WordPress
CVE-2026-65512

5.4MEDIUM

What is CVE-2026-65512?

The WP Activity Log plugin for WordPress versions up to 5.6.4 is susceptible to an unauthenticated Cross Site Request Forgery (CSRF) vulnerability. This flaw allows attackers to trick users into executing unwanted actions on their behalf without proper authentication, potentially compromising site security. It is essential for administrators to update to a patched version to mitigate any risks associated with this vulnerability.

Affected Version(s)

WP Activity Log 0 <= 5.6.4

WP Activity Log Premium 0 <= 5.6.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Levon Balyan | Patchstack Bug Bounty Program
.