CVE Published: 24/07/2023 |
CVE Updated: 24/10/2024 |
CVE Year: 2023 Source: WPScan |
Vendor: Unknown |
Product: User Activity Log Status : PUBLISHED
CVE-2023-2761 Description
The User Activity Log WordPress plugin before 1.6.3 does not properly sanitise and escape the `txtsearch` parameter before using it in a SQL statement in some admin pages, leading to a SQL injection exploitable by high privilege users such as admin.