CVE-2026-65512
published 2026-07-23CVE-2026-65512: Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery. This…
PriorityP421medium5.4CVSS 3.1
AVNACLPRNUIRSUCNILAL
EPSS
0.14%
4.0th percentile
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.
This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| melapress | wp_activity_log | <= 5.6.4 | — |
| melapress | wp_activity_log_premium | <= 5.6.4 | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
ghsa_unreviewed·2026-07-23
CVE-2026-65512 [MEDIUM] CWE-352 Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions.
Red Hat
nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
vendor_redhat·2026-06-25·CVSS 8.8
CVE-2026-12244 [HIGH] CWE-787 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes
A flaw was found in nsd. When nsd is configured as a secondary server for a zone, a remote attacker, acting as the primary server for that zone, can send a specially crafted DNS message within an AXFR (Asynchronous Full Zone Transfer) request. This message, containing a malformed SVCB (Se
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [fedora-all]
bugzilla·2026-06-29·CVSS 8.8
CVE-2026-12244 [HIGH] CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [fedora-all]
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes.
Even though the data is from a conf
Bugzilla
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [epel-all]
bugzilla·2026-06-29·CVSS 8.8
CVE-2026-12244 [HIGH] CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [epel-all]
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes. [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes.
Even though the data is from a config
Bugzilla
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
bugzilla·2026-06-22·CVSS 8.8
CVE-2026-12244 [HIGH] CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
CVE-2026-12244 nsd: A specially crafted SVCB RR can cause a heap overflow of up to 65509 attacker controlled bytes.
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (RCE class) head write of up to 65509 bytes.
Even though the data is from a configured primary inside NSD's trust boundary, we do consider the risk significant enough for multi-tenant secondary DNS deployments, given the potential severity of the attack.
https://patchstack.com/database/WordPress/Plugin/wp-security-audit-log-premium/vulnerability/wordpress-wp-activity-log-premium-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerabilityhttps://patchstack.com/database/wordpress/plugin/wp-security-audit-log/vulnerability/wordpress-wp-activity-log-plugin-5-6-4-cross-site-request-forgery-csrf-vulnerability?_s_id=cve
2026-07-23
Published