CVE-2025-0767

WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.
Configurations

Configuration 1 (hide)

cpe:2.3:a:melapress:wp_activity_log:5.3.2:*:*:*:*:wordpress:*:*

History

21 May 2025, 17:06

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Se descubrió que WP Activity Log 5.3.2 era vulnerable. La entrada de usuario no validada se utiliza directamente en una función de anulación de serialización en myapp/classes/Writers/class-csv-writer.php.
CPE cpe:2.3:a:melapress:wp_activity_log:5.3.2:*:*:*:*:wordpress:*:*
References () https://co.wordpress.org/plugins/wp-security-audit-log/ - () https://co.wordpress.org/plugins/wp-security-audit-log/ - Product
References () https://fluidattacks.com/advisories/skims-9/ - () https://fluidattacks.com/advisories/skims-9/ - Third Party Advisory
First Time Melapress wp Activity Log
Melapress

27 Feb 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 19:15

Updated : 2025-05-21 17:06


NVD link : CVE-2025-0767

Mitre link : CVE-2025-0767

CVE.ORG link : CVE-2025-0767


JSON object : View

Products Affected

melapress

  • wp_activity_log
CWE
CWE-502

Deserialization of Untrusted Data