CVE-2023-2261
published 2023-06-09CVE-2023-2261: The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions…
PriorityP421medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.55%
44.7th percentile
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with subscriber-level access or higher, to obtain a list of users with accounts on the site. This includes ids, usernames and emails.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| melapress | wp_activity_log | <= 4.5.0 | — |
| wpwhitesecurity | wp_activity_log | <= 4.5.0 | — |
| wpwhitesecurity | wp_activity_log_premium | <= 4.5.0 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
WP Activity Log Plugin up to 4.5.0 on WordPress information disclosure
vuldb·2026-04-10·CVSS 4.3
CVE-2023-2261 [MEDIUM] WP Activity Log Plugin up to 4.5.0 on WordPress information disclosure
A vulnerability described as problematic has been identified in WP Activity Log Plugin up to 4.5.0 on WordPress. The impacted element is an unknown function. Such manipulation leads to information disclosure.
This vulnerability is documented as CVE-2023-2261. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-6j8v-vqm5-qg95: The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in v
ghsa_unreviewed·2023-06-09
CVE-2023-2261 [MEDIUM] CWE-862 GHSA-6j8v-vqm5-qg95: The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in v
The WP Activity Log plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the handle_ajax_call function in versions up to, and including, 4.5.0. This makes it possible for authenticated attackers, with subscriber-level access or higher, to obtain a list of users with accounts on the site. This includes ids, usernames and emails.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://plugins.trac.wordpress.org/browser/wp-security-audit-log/trunk/vendor/wpwhitesecurity/select2-wpwhitesecurity/load.php#L70https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2911239%40wp-security-audit-log%2Ftrunk&old=2897171%40wp-security-audit-log%2Ftrunk&sfp_email=&sfph_mail=https://www.wordfence.com/threat-intel/vulnerabilities/id/f51f0919-498e-4f86-a933-1b7f2c4a10a4?source=cvehttps://plugins.trac.wordpress.org/browser/wp-security-audit-log/trunk/vendor/wpwhitesecurity/select2-wpwhitesecurity/load.php#L70https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2911239%40wp-security-audit-log%2Ftrunk&old=2897171%40wp-security-audit-log%2Ftrunk&sfp_email=&sfph_mail=https://www.wordfence.com/threat-intel/vulnerabilities/id/f51f0919-498e-4f86-a933-1b7f2c4a10a4?source=cve
2023-06-09
Published