Plainview Activity Monitor

Plainview Activity Monitor has one disclosed vulnerability in the WordSec catalog, all reported in 2018; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is OS Command Injection, behind 1 of the records (100%).

The one issue recorded for Plainview Activity Monitor has a vendor fix available, so running the current release closes it.

Plainview Activity Monitor is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 4.9.31.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Plainview Activity Monitor vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2018-15877

Plainview Activity Monitor < 20180826 - Remote Command Injection

Read the full analysis

Vulnerability Records

1 records
Plainview Activity Monitor banner
Latestv20180826

Plainview Activity Monitor

edward_plainview

Author

edward_plainview

3.6(12)
72/100
Last Updated
2018-08-26 (8y ago)
Active Installs
100+
Downloads
29,426
Requires WP
3.9+
Requires PHP
0+
Tested up to
WP 4.9.31
Created
2014-05-11 (13y ago)

Activity Monitor tracks all user activity on your blog or network. The activities can be viewed in global table showing activities on the whole network, or locally for just the blog you are currently viewing. The activites can be filtered so that only specific blogs / hooks / IPs / users are displayed. Monitored actions include (not exhaustive): Comments: approve, held, spam, delete Custom Post Types: draft, publish, update, trash, delete Logins: login, login failed, logout Pageviews: admin, front-end Passwords: reset, retrieve Plugins: activate, deactivate Pages: draft, publish, update, trash, delete Posts: draft, publish, update, trash, delete, password Taxonomies: create, edit, delete Themes: switched Updates: WordPress core, plugins, themes Users: register, delete, profile changes And more…. The logged information consists of: A description of what was logged Blog Timestamp Hook that was triggered User ID git The Activity Monitor has a git repository. Security tips There are several ways for people to break in to your WordPress installation, or cause trouble by DDOS. Here are some tips on how to use the Activity Monitor and its plugins to help detect problems: Get a DDOS protection service with an API. There is a plugin to ban IPs via CloudFlare (Send To CloudFlare). Other APIs could be supported as the need arises. If you have another DDOS service, write a script that can ban visitors by IP. Use this script with the Send To Exec plugin. If you can’t ban users using a script, at least set up the Send To E-mail plugin to inform you of suspicious activity. Use the Bruteforce Detect plugin to detect when an IP or IPs are trying to guess the admin’s password. Ban the IPs automatically using Send To Exec. Do not use admin as the username for your administrator account. Instead, use some else and add the admin username to the list of banned usernames in the Login Failed Username plugin. Ban the IPs that cause the plugin to react. Custom hooks See the developer documentation for relevant info on how to create custom hooks.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C