User Activity Log [user-activity-log] <= 2.2 (unfixed)
unknown
[en] The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 28, 2026
CVE-2025-13471 on NVD →
User Activity Log [user-activity-log] <= 2.2 (unfixed)
unknown
[en] The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push s...
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 7, 2026
CVE-2025-11877 on NVD →
User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login
high
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push select...
- CVSS:
- 7.5
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-11877 on NVD →
User Activity Log <= 2.2 - Unauthenticated Limited Arbitrary Option Update
medium
The User Activity Log plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check in all versions up to, and including, 2.2. This makes it possible for unauthenticated attackers to update option values to one on the WordPress site. This...
- CVSS:
- 5.3
- Affected:
- up to 2.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 6, 2026
CVE-2025-13471 on NVD →
User Activity Log [user-activity-log] < 2.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log.This issue affects User Activity Log: from n/a through 1.8.
- Affected:
- up to 2.0
- Fixed in:
- 2.0
- Disclosed:
- Apr 10, 2024
CVE-2024-31356 on NVD →
User Activity Log <= 1.9 - Authenticated (Administrator+) SQL Injection
critical
The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.9 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access a...
- CVSS:
- 9.1
- Affected:
- up to 1.9
- Fixed in:
- 2.0
- Disclosed:
- Apr 7, 2024
CVE-2024-31356 on NVD →
User Activity Log [user-activity-log] < 1.6.3
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solwin Infotech User Activity Log user-activity-log allows SQL Injection.This issue affects User Activity Log: from n/a through 1.6.2.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Oct 31, 2023
CVE-2023-37966 on NVD →
User Activity Log [user-activity-log] < 1.6.6
unknown
[en] The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Sep 4, 2023
CVE-2023-4269 on NVD →
User Activity Log [user-activity-log] < 1.6.7
unknown
[en] This User Activity Log WordPress plugin before 1.6.7 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to hide the source of malicious traffic.
- Affected:
- up to 1.6.7
- Fixed in:
- 1.6.7
- Disclosed:
- Sep 4, 2023
CVE-2023-4279 on NVD →
User Activity Log <= 1.6.6 - IP Address Spoofing
medium
The User Activity Log plugin for WordPress is vulnerable to IP Address Spoofing in versions up to and including 1.6.6. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging. Attackers can supplied the X-Forwarded-For header with with a different IP Address t...
- CVSS:
- 5.3
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.7
- Disclosed:
- Aug 14, 2023
CVE-2023-4279 on NVD →
User Activity Log [user-activity-log] < 1.6.5
unknown
[en] The User Activity Log WordPress plugin before 1.6.5 does not correctly sanitise and escape several parameters before using it in a SQL statement as part of its exportation feature, allowing unauthenticated attackers to conduct SQL injection attacks.
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.5
- Disclosed:
- Aug 14, 2023
CVE-2023-3435 on NVD →
User Activity Log [user-activity-log] < 1.6.6
unknown
Update the WordPress User Activity Log plugin to the latest available version (at least 1.6.6).
WordFence discovered and reported this Broken Access Control vulnerability in WordPress User Activity Log Plugin. A broken access control issue refers to a missing authorization, authentication or nonce token check in a func...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Aug 9, 2023
User Activity Log <= 1.6.5 - Unauthenticated Data Export to Sensitive Information Disclosure
high
The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.4 via the ual_export_log() function that is missing a capability check. This can allow unauthenticated attackers to extract sensitive data including user roles, usernames, and IP Addresses. T...
- CVSS:
- 7.5
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Aug 8, 2023
CVE-2023-4269 on NVD →
User Activity Log [user-activity-log] < 1.6.6
unknown
The User Activity Log plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 1.6.4 via the ual_export_log() function that is missing a capability check. This can allow unauthenticated attackers to extract sensitive data including user roles, usernames, and IP Addresses. T...
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Aug 8, 2023
User Activity Log <= 1.6.4 - Unauthenticated SQL Injection
high
The User Activity Log plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.6.4 via the ual_export_log() and ual_export_user_log() function that is missing preparation on existing queries as well as escaping on the user input passed to them. This makes it possible for unauthenticated a...
- CVSS:
- 7.5
- Affected:
- up to 1.6.4
- Fixed in:
- 1.6.5
- Disclosed:
- Jul 24, 2023
CVE-2023-3435 on NVD →
User Activity Log [user-activity-log] < 1.6.3
unknown
[en] The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Jul 24, 2023
CVE-2023-2761 on NVD →
User Activity Log <= 1.6.2 - Unauthenticated SQL Injection via username
high
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the username value when logging in in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the ual_shook_wp_login_failed funct...
- CVSS:
- 8.1
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Jul 14, 2023
User Activity Log [user-activity-log] < 1.6.3
unknown
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the username value when logging in in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the ual_shook_wp_login_failed funct...
- Affected:
- up to 1.6.3
- Fixed in:
- 1.6.3
- Disclosed:
- Jul 14, 2023
User Activity Log <= 1.6.2 - Authenticated (Administrator+) SQL Injection
high
The User Activity Log plugin for WordPress is vulnerable to SQL Injection via several parameters like 'userrole', 'userip', 'username', and 'type' in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the ual_u...
- CVSS:
- 7.2
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- Jul 12, 2023
CVE-2023-37966 on NVD →
User Activity Log <= 1.6.2 - Authenticated(Administrator+) SQL Injection via txtsearch
medium
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the ‘txtsearch’ parameter in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- CVSS:
- 6.6
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.3
- Disclosed:
- May 25, 2023
CVE-2023-2761 on NVD →
User Activity Log [user-activity-log] < 1.6.2
unknown
The User Activity Log plugin for WordPress is vulnerable to generic SQL Injection via the ‘txtsearch’ parameter in versions up to, and including, 1.6.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated atta...
- Affected:
- up to 1.6.2
- Fixed in:
- 1.6.2
- Disclosed:
- May 25, 2023
User Activity Log <= 1.4.6 - Reflected Cross Site Scripting
medium
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "$_SERVER['QUERY_STRING']" in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- CVSS:
- 6.1
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 30, 2021
User Activity Log <= 1.4.6 - Reflected Cross-Site Scripting
medium
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘txtsearch’ parameter in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- CVSS:
- 6.1
- Affected:
- up to 1.4.6
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 30, 2021
User Activity Log [user-activity-log] < 1.4.7
unknown
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the "$_SERVER['QUERY_STRING']" in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages...
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 30, 2021
User Activity Log [user-activity-log] < 1.4.7
unknown
The User Activity Log plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘txtsearch’ parameter in versions up to, and including, 1.4.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that...
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
- Disclosed:
- Aug 30, 2021
User Activity Log [user-activity-log] < 1.2.6
unknown
There's no escaping done for $from_email and $to_email variables. Also, there's missing a nonce check.
Update the plugin.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- Jul 29, 2017
User Activity Log [user-activity-log] < 1.4.7
unknown
The plugin does not escape the txtsearch parameter before outputting it in an attribute, leading to a Reflected Cross-Site Scripting issue
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
User Activity Log [user-activity-log] < 1.4.7
unknown
The plugin does not escape the $_SERVER['QUERY_STRING'] before outputting it back in attributes, which could lead to Reflected Cross-Site Scripting in web browsers which do not encode URL characters.
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.7
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database