CVE-2026-65512: WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allows Cross Site Request Forgery.
This issue affects WP Activity Log: through 5.6.4; WP Activity Log Premium: through 5.6.4.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Melapress WP Activity Log Premiumto a version that resolves this vulnerability.Fixed in 5.6.5 - Upgrade
Upgrade
Melapress WP Activity Logto a version that resolves this vulnerability.Fixed in 5.6.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-65512?
The severity of CVE-2026-65512 is classified as medium with a score of 5.4.
How do I fix CVE-2026-65512?
To fix CVE-2026-65512, upgrade the WP Activity Log plugin to version 5.6.5 or later.
What type of vulnerability is CVE-2026-65512?
CVE-2026-65512 is a Cross Site Request Forgery (CSRF) vulnerability affecting the WP Activity Log plugin.
Who is affected by CVE-2026-65512?
Anyone using WP Activity Log versions 5.6.4 or earlier is potentially vulnerable to CVE-2026-65512.
Is authentication required to exploit CVE-2026-65512?
No, CVE-2026-65512 is an unauthenticated vulnerability, meaning it can be exploited without user authentication.