CVE-2023-4269
User Activity Log < 1.6.6 - Subscriber+ Log Export
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
El complemento de WordPress Registro de Actividad del Usuario anterior a 1.6.6 carece de la autorización adecuada al exportar sus registros de actividad, lo que permite a cualquier usuario autenticado, como un suscriptor, realizar dicha acción y recuperar PII, como direcciones de correo electrónico.
The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.4 via the ual_export_log() function that is missing a capability check. This can allow unauthenticated attackers to extract sensitive data including user roles, usernames, and IP Addresses. This issue was partially patched in 1.6.4, which made it only exploitable by authenticated users, and a full patch was released in 1.6.6.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-08 CVE Published
- 2023-08-09 CVE Reserved
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://wpscan.com/vulnerability/db3e4336-117c-47f2-9b43-2ca115525297 | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Solwininfotech Search vendor "Solwininfotech" | User Activity Log Search vendor "Solwininfotech" for product "User Activity Log" | < 1.6.6 Search vendor "Solwininfotech" for product "User Activity Log" and version " < 1.6.6" | wordpress |
Affected
|