WP Activity Log Unauthenticated PHP Object Injection Vulnerability

Vulnerability

A vulnerability in the WP Activity Log plugin, specifically in version 5.3.2, allows for PHP object injection due to unvalidated user input being directly passed to an unserialize function. This issue is located in the file 'myapp/classes/Writers/class-csv-writer.php'.

Impact

Exploitation of this vulnerability could lead to PHP object injection, allowing attackers to manipulate object properties and potentially execute arbitrary code, depending on the context of the injected object.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
10.0
exploitability
6.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.