icon

We found results for “

CVE-2020-36716

Good to know:

icon

Date: June 6, 2023

The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin configuration options.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Missing Authorization

CWE-862

Top Fix

icon

Upgrade Version

Upgrade to version 4.0.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us