Extension WordPress
Vulnérabilités User Activity Log
Cette page rassemble les failles publiées pour User Activity Log, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User Activity Log
11 fiches
User Activity Log <= 2.2 – Unauthenticated Limited Options Update via Failed Login
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it…
*-2.2
Non indiqué
06/01/2026
User Activity Log <= 2.2 – Unauthenticated Limited Arbitrary Option Update
The User Activity Log plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check in all versions up to, and including, 2.2. This makes…
*-2.2
Non indiqué
06/01/2026
User Activity Log <= 1.9 – Authenticated (Administrator+) SQL Injection
The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…
*-1.9
2.0
07/04/2024
User Activity Log <= 1.6.6 – IP Address Spoofing
The User Activity Log plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.6.6. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging.…
*-1.6.6
1.6.7
14/08/2023
User Activity Log <= 1.6.5 – Unauthenticated Data Export to Sensitive Information Disclosure
The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.4 via the ual_export_log() function that is missing a capability check. This can allow unauthenticated attackers to extract sensitive…
*-1.6.5
1.6.6
08/08/2023
User Activity Log <= 1.6.4 – Unauthenticated SQL Injection
The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.4 via the ual_export_log() and ual_export_user_log() function that is missing preparation on existing queries as well as escaping on the…
*-1.6.4
1.6.5
24/07/2023
User Activity Log <= 1.6.2 – Unauthenticated SQL Injection via username
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the username value when logging in in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack…
*-1.6.2
1.6.3
14/07/2023
User Activity Log <= 1.6.2 – Authenticated (Administrator+) SQL Injection
The User Activity Log plugin for WordPress is vulnerable to SQL Injection via several parameters like 'userrole', 'userip', 'username', and 'type' in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and…
*-1.6.2
1.6.3
12/07/2023
User Activity Log <= 1.6.2 – Authenticated(Administrator+) SQL Injection via txtsearch
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the ‘txtsearch’ parameter in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…
*-1.6.2
1.6.3
25/05/2023
User Activity Log <= 1.4.6 – Reflected Cross Site Scripting
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "$_SERVER['QUERY_STRING']" in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…
*-1.4.6
1.4.7
30/08/2021
User Activity Log <= 1.4.6 – Reflected Cross-Site Scripting
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘txtsearch’ parameter in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…
*-1.4.6
1.4.7
30/08/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.