VYPR

coreActivity: Activity Logging

by WordPress

Source repositories

CVEs (2)

  • CVE-2026-7635HigMay 13, 2026
    risk 0.46cvss 8.1epss 0.00

    The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0. This is due to the plugin failing to validate or strip PHP serialization syntax from the User-Agent HTTP header before storing…

  • CVE-2024-0868MedApr 17, 2024
    risk 0.34cvss 5.3epss 0.00

    The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value