WP System Log - Broken Access Control vulnerability
mediumBroken Access Control vulnerability
- CVSS:
- 6.5
- Affected:
- up to 1.2.7
- Fixed in:
- 1.2.8
- Disclosed:
- Mar 17, 2026
plugin
5 known security issues reported for the Winterlock WordPress plugin. Most recent disclosed Mar 17, 2026.
Running Winterlock on your site? Check whether your installed version is affected.
Scan your site freeBroken Access Control vulnerability
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.
The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view...
The Activity Log WinterLock plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete log data via a forged request granted they c...
The WP System Log WordPress plugin before 1.0.21 does not sanitise, validate and escape the IP address retrieved from login requests before outputting them in the admin dashboard, which could allow unauthenticated attacker to perform Cross-Site Scripting attacks against admins viewing the logs.
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free