CVE-2026-84759: WordPress Activity Log plugin <= 2.13.1 - Cross Site Request Forgery (CSRF) vulnerability
Published Sep 2, 2026
·Updated
Unauthenticated Cross Site Request Forgery (CSRF) in Activity Log <= 2.13.1 versions.
Affected Software
1 affected component
WordPress Activity Log plugin<=2.13.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Activity Log pluginto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Sep 2, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
WordPress sites using the Activity Log plugin at version 2.13.1 or earlier are affected.
2
Does exploitation require an authenticated attacker?
No. The vulnerability is described as unauthenticated CSRF, so the attacker does not need an account on the affected WordPress site.
3
What user interaction is required for exploitation?
The CVSS vector indicates user interaction is required. An attacker would need a user to trigger the forged request.