Extension WordPress
Vulnérabilités coreActivity: Activity Logging for WordPress
Cette page rassemble les failles publiées pour coreActivity: Activity Logging for WordPress, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de coreActivity: Activity Logging for WordPress
4 fiches
coreActivity: Activity Logging for WordPress <= 3.0 – Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from…
*-3.0
3.1
12/05/2026
coreActivity: Activity Logging for WordPress <= 2.7 – Authenticated (Subscriber+) SQL Injection
The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'order' and 'orderby' parameters in all versions up to, and including, 2.7 due to insufficient escaping on the user supplied parameter and…
*-2.7
2.7.1
07/04/2025
coreActivity <= 2.0.1 – IP Spoofing
The coreActivity: Activity Logging plugin for WordPress plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.1 due to insufficient IP address validation and use of user-supplied HTTP headers as a…
*-2.0.1
2.1
27/03/2024
coreActivity <= 1.8 – Unauthenticated Stored Cross-Site Scripting
The coreActivity plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an unknown parameter in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping. This makes it possible…
*-1.8
1.8.1
26/01/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.