cleantalk
Vulnerabilities and Security Researches

WP Activity Log, 423db6f18e40bada4f753f75004f47b51c4f8620

Application

WP Activity Log

Published on
Jun 27, 2017
Research Description
WP Activity Log [wp-security-audit-log] < 2.4.4 WordPress WP Security Audit Log plugin <= 2.4.3 - Reflected Cross-Site Scripting (XSS) Vulnerability Reflected Cross-Site Scripting (XSS) Vulnerability exists in AjaxDisableCustomField() function, in the file /wp-security-audit-log.php. The "notice" variable is printed on the front-end without escaping it. Update the plugin.
Affected versions
max 2.4.4.
Status
vulnerable