Impact
The vulnerability resides in the winter_activity_log_action() function of the Activity Log for WordPress plugin, where a missing capability check allows an attacker to read log files. An authenticated user with Subscriber level or higher can trigger this function and obtain content that may contain sensitive data such as the passwords of higher‑privilege users. This flaw therefore enables credential disclosure and potential escalation of privilege for an authenticated attacker.
Affected Systems
Switcorp Activity Log for WordPress plugin versions 1.2.8 and any earlier release are affected. The issue is present in all builds up to and including 1.2.8.
Risk and Exploitability
The vulnerability has a severity score of 6.5, indicating moderate risk, while the likelihood of exploitation is low, with a probability estimate below 1%. The attack requires an authenticated user with a Subscriber role or higher to trigger the action and read the log file. No additional privileges or special setup are needed, so any site running the vulnerable plugin can be impacted. The vulnerability is not listed in the national known exploited vulnerability catalog.
OpenCVE Enrichment