cleantalk
Vulnerabilities and Security Researches

WP Activity Log, 6dae6dca-7474-4008-9fe5-4c62b9f12d0a

Application

WP Activity Log

Published on
-
Research Description
WP Activity Log [wp-security-audit-log] < 4.4.0 Unauthorised AJAX Calls via Freemius The plugins and themes use an insecure version of the Freemius Framework, which is lacking CSRF and/or authorisation in some of its AJAX actions. As a result, any authenticated users, such as subscriber could access the debug logs. Unauthenticated attackers could also make a logged in admin toggle the debug mode via a CSRF attack.
Affected versions
max 4.4.0.
Status
vulnerable