WP Security Audit Log <= 3.1.1 - Sensitive Information Disclosure

2018-03-28 00:00
Colette Chamberland

Strategic Overview

Status
Patched in 3.1.2
Affected PluginWP Activity Log
Affected Version<= 3.1.1
CVSS5.3Medium
CVECVE-2018-8719
View all WP Activity Log vulnerabilities

Vulnerability Overview

An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

Technical Analysis

REMEDIATION: Update to version 3.1.2, or a newer patched version --- IDENTIFIER: CWE-532 (Insertion of Sensitive Information into Log File) The product writes sensitive information to a log file.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C