VYPR

Wp Security Audit Log

by Wpsecurityauditlog

CVEs (2)

  • CVE-2014-5072HigApr 6, 2018
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in WP Security Audit Log plugin before 1.2.5 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

  • CVE-2018-8719MedApr 4, 2018
    risk 0.39cvss 5.3epss 0.13

    An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.