CVE-2026-45435: WordPress WP Activity Log plugin <= 5.6.3 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.
This issue affects WP Activity Log: from n/a through 5.6.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Melapress WP Activity Logto a version that resolves this vulnerability.Fixed in 5.6.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45435?
CVE-2026-45435 has a medium severity rating of 6.5.
How do I fix CVE-2026-45435?
To fix CVE-2026-45435, update the WordPress WP Activity Log plugin to at least version 5.6.3.1.
What type of vulnerability is CVE-2026-45435?
CVE-2026-45435 is classified as a Cross-Site Scripting (XSS) vulnerability.
Which versions of the WP Activity Log plugin are affected by CVE-2026-45435?
CVE-2026-45435 affects all versions of WP Activity Log from n/a through 5.6.3.
What impact does CVE-2026-45435 have on users?
CVE-2026-45435 can lead to DOM-Based XSS, allowing attackers to execute malicious scripts in the context of user sessions.