logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2020-36716

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2020-36716

Description:
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the setup_page function in versions up to, and including, 4.0.1. This makes it possible for unauthenticated attackers to run the setup wizard (if it has not been run previously) and access plugin configuration options.
Last updated date:
06/12/2023
Type:
exploit
Confidence:
HIGH
Date of publishing:
06/12/2023
Reference url to background

https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-wp-security-audit-log-plugin/

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy