Impact
The CVE description identifies a stored cross‑site scripting flaw in the Melapress WP Activity Log plugin, affecting versions up to 5.6.3.1. The flaw is caused by insufficient input sanitization when generating the activity log, which permits an attacker to inject malicious JavaScript that is stored and later executed in the browser of anyone with access to view the log. Based on the description, it is inferred that the attacker could potentially execute arbitrary scripts in the victim’s browser context, which could facilitate credential theft, page defacement, or redirection to malicious sites. The weakness is classified as CWE-79.
Affected Systems
The affected software is the WordPress WP Activity Log plugin from Melapress, with all releases up to but not including 5.6.4 vulnerable. Any WordPress installation that has a version of this plugin older than 5.6.4 should be considered at risk.
Risk and Exploitability
With a CVSS score of 7.1 this vulnerability is considered high severity. The EPSS score is < 1%, indicating a low but non-zero likelihood of exploitation, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves the WordPress web interface and would target users with the subscriber role who can view the log.
OpenCVE Enrichment