WP Activity Log <= 4.0.1 - Missing Authorization

2020-03-08 00:00
Jerome Bruandet

Strategic Overview

Status
Patched in 4.0.2
Affected PluginWP Activity Log
Affected Version< 4.0.2
CVSS7.3High
CVECVE-2020-36716
View all WP Activity Log vulnerabilities

Vulnerability Overview

The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin configuration options.

Technical Analysis

REMEDIATION: Update to version 4.0.2, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C