cleantalk
Vulnerabilities and Security Researches

User Activity Log, CVE-2025-13471

CVE, Research URL

CVE-2025-13471

Application

User Activity Log

Published on
Jan 28, 2026
Research Description
The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)
Affected versions
max 2.2.
Status
vulnerable