CVE-2026-54806: WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability
Published Jun 17, 2026
·Updated
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
Affected Software
1 affected component
WP White Security WP Activity Log<=5.6.3.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Activity Log Pluginto a version that resolves this vulnerability.Fixed in 5.6.4
Event History
Jun 17, 2026
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-54806?
CVE-2026-54806 has a severity rating of 9.8, which is considered critical.
2
How do I fix CVE-2026-54806?
To fix CVE-2026-54806, upgrade the WP Activity Log plugin to version 5.6.3.2 or later.
3
What is the impact of CVE-2026-54806?
CVE-2026-54806 allows unauthenticated PHP Object Injection, potentially leading to remote code execution.
4
Who is affected by CVE-2026-54806?
CVE-2026-54806 affects all users of the WP Activity Log plugin versions 5.6.3.1 and earlier.
5
When was CVE-2026-54806 published?
CVE-2026-54806 was published on June 17, 2026.