Vulnerabilities
Vulnerable Software
Dev4press:  >> Coreactivity  Security Vulnerabilities
The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin
CVSS Score
6.1
EPSS Score
0.002
Published
2025-05-15
The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them by providing an arbitrary value
CVSS Score
5.3
EPSS Score
0.002
Published
2024-04-17


Contact Us

Shodan ® - All rights reserved