Description
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.

This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
Published: 2026-07-23
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The updated description reveals a CSRF flaw in the WordPress WP Activity Log and WP Activity Log Premium plugins that permits attackers to submit requests without proper nonce verification. This weakness allows anyone who can trigger the vulnerable endpoint to perform any action authorized for the current user role within the plugin, potentially including altering audit logs or taking administrative actions. Crucially, the flaw remains unauthenticated, so no credentials are required.

Affected Systems

The affected system is the WordPress WP Activity Log plugin and WP Activity Log Premium plugin offered by Melapress. All installations of either plugin up to and including version 5.6.4 are impacted. The plugins are commonly used on WordPress sites for audit logging and security monitoring.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, and the very low EPSS score (< 1%) suggests limited exploitation activity as of the last assessment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted HTTP request sent from a third‑party site to a vulnerable WordPress instance, inferred from the nature of CSRF. Successful exploitation requires no user credentials, meaning any visitor could be targeted if they trigger the malicious request.

Generated by OpenCVE AI on August 5, 2026 at 10:52 UTC.

Remediation

Vendor Solution

Update the WordPress WP Activity Log plugin to the latest available version (at least 5.6.5).


OpenCVE Recommended Actions

  • Apply the latest WP Activity Log plugin version (5.6.5 or newer).
  • Apply the latest WP Activity Log Premium plugin version (5.6.5 or newer).
  • If an upgrade cannot be applied immediately, deactivate or remove the vulnerable plugin instance.
  • Deploy or configure a web application firewall to detect and block suspicious CSRF request patterns.
  • Review and restrict user roles that have administration rights to the WP Activity Log plugin to enforce least privilege.

Generated by OpenCVE AI on August 5, 2026 at 10:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
Title WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability
References

Thu, 23 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Melapress
Melapress wp Activity Log
Wordpress
Wordpress wordpress
Vendors & Products Melapress
Melapress wp Activity Log
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
Title WordPress WP Activity Log plugin <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Melapress Wp Activity Log
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-05T08:36:51.179Z

Reserved: 2026-07-22T08:53:52.510Z

Link: CVE-2026-65512

cve-icon Vulnrichment

Updated: 2026-07-23T13:40:46.339Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:44.253

Modified: 2026-08-05T09:18:15.727

Link: CVE-2026-65512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T11:00:12Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)