The User Activity Tracking and Log WordPress plugin prior to 4.0.9 does not have proper CSRF checks when managing its license, which could allow malicious users to make logged in admins update and deactivate the plugin's license via CSRF attacks
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mooveagency user activity tracking and log |