WP Activity Log, 423db6f18e40bada4f753f75004f47b51c4f8620
- CVE, Research URL
- Home page URL
- Application
- Published on
- Jun 27, 2017
- Research Description
- WP Activity Log [wp-security-audit-log] < 2.4.4 WordPress WP Security Audit Log plugin <= 2.4.3 - Reflected Cross-Site Scripting (XSS) Vulnerability Reflected Cross-Site Scripting (XSS) Vulnerability exists in AjaxDisableCustomField() function, in the file /wp-security-audit-log.php. The "notice" variable is printed on the front-end without escaping it. Update the plugin.
- Affected versions
-
max 2.4.4.
- Status
-
vulnerable