Melapress WP Activity Log
cpe:2.3:a:melapress:wp_activity_log:*:*:*:*:wordpress:*:*
- 5.3.2
A vulnerability in the WP Activity Log plugin, specifically in version 5.3.2, allows for PHP object injection due to unvalidated user input being directly passed to an unserialize function. This issue is located in the file 'myapp/classes/Writers/class-csv-writer.php'.
Exploitation of this vulnerability could lead to PHP object injection, allowing attackers to manipulate object properties and potentially execute arbitrary code, depending on the context of the injected object.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.