coreActivity: Activity Logging for WordPress
coreActivity: Activity Logging for WordPress has 4 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2026; all 4 are fixed as of September 2026. Their average CVSS score is 6.8, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 2 high. 2024 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 1 of the records (25%). Other recurring categories include Deserialization Of Untrusted Data, SQL Injection.
Every one of the 4 issues recorded for coreActivity: Activity Logging for WordPress has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, one record each. coreActivity: Activity Logging for WordPress is installed on roughly 10 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2026-7635coreActivity: Activity Logging for WordPress <= 3.0 - Unauthenticated PHP Object Injection via 'user_agent' Log Meta Field
Read the full analysisVulnerability Records

coreActivity: Activity Logging for WordPress
Author
Milan Petrovic
CoreActivity is a free plugin for monitoring and logging various activities of the WordPress powered website. The plugin is highly modular, with events registered and controlled by multiple Components. Quick Introduction Video Currently, plugin has 28 components with a total of 182 events, with direct integration with 12 popular plugins. WordPress Core Components Attachments (3 events) Comments (5 events) Errors (6 events) Notifications (4 events) Options (7 events) Plugins (9 events) Posts (6 events) Privacy (10 events) Terms (6 events) Themes (6 events) Users (21 events) WordPress (8 events) REST API (8 events) WordPress Network Only Components Multisite Network (15 events) Sitemeta (7 events) CoreActivity Internal Component Internal (4 events) Third-party Plugins Components bbPress (6 events) BuddyPress (4 events) Contact Form 7 (3 events) DebugPress (9 event) Duplicate Post (1 event) Forminator (1 event) GD Forum Manager (4 event) Gravity Forms (6 events) Jetpack (2 events) SweepPress (11 event) User Switching (4 events) WooCommerce (6 events) Geo Location of IPs The plugin can locate where the IP making the request is coming from. There are currently three methods available, with more coming in the future: Online via GeoJS.io website IP2Location Local Database MaxMind GeoLite2 Local Database To use IP2Location, you need to have an account on IP2Location, to get the download token, and getting the Lite versions of the database is free. To use MaxMind GeoLite2, you need to have MaxMind account, and the license for downloading the files, it is free for the GeoLite2 database files. Plugin supports use of all Lite databases for both providers, and using the provided token it can keep the database updated on a weekly basis. More Features Instant Notifications Daily Digest Notifications Weekly Digest Notifications IP WhoIs Information Request Device Detection Users login, logout, online tracking Log Cleanup Tools Auto Log Cleanup Log Live Updates Define Exceptions Home, Documentation and GitHub Learn more about the plugin: CoreActivity Website Plugin Knowledge Base: CoreActivity Support Contribute to plugin development: CoreActivity on GitHub
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C