CVE-2026-62085: WordPress WP Activity Log plugin <= 5.6.6 - SQL Injection vulnerability
Published Sep 30, 2026
·Updated
Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.
Affected Software
1 affected component
WordPress WP Activity Log<=5.6.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP Activity Log pluginto a version that resolves this vulnerability.Fixed in 5.6.7
Event History
Sep 30, 2026
CVE Published
via MITRE·12:26 PM
Data Sourced
via MITRE·12:26 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs high privileges. The description identifies this as an administrator SQL injection issue.
2
Can this be exploited remotely without user interaction?
Yes. The CVSS vector lists network access, low attack complexity, and no user interaction.
3
What versions are affected?
WP Activity Log versions 5.6.6 and earlier are identified as affected.
4
What is the potential impact?
The CVSS vector indicates high confidentiality impact and low availability impact. It indicates no integrity impact.