Impact
The updated description reveals a CSRF flaw in the WordPress WP Activity Log and WP Activity Log Premium plugins that permits attackers to submit requests without proper nonce verification. This weakness allows anyone who can trigger the vulnerable endpoint to perform any action authorized for the current user role within the plugin, potentially including altering audit logs or taking administrative actions. Crucially, the flaw remains unauthenticated, so no credentials are required.
Affected Systems
The affected system is the WordPress WP Activity Log plugin and WP Activity Log Premium plugin offered by Melapress. All installations of either plugin up to and including version 5.6.4 are impacted. The plugins are commonly used on WordPress sites for audit logging and security monitoring.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity, and the very low EPSS score (< 1%) suggests limited exploitation activity as of the last assessment. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted HTTP request sent from a third‑party site to a vulnerable WordPress instance, inferred from the nature of CSRF. Successful exploitation requires no user credentials, meaning any visitor could be targeted if they trigger the malicious request.
OpenCVE Enrichment