4.3
CVSSv3

CVE-2023-4269

Published: 04/09/2023 Updated: 07/11/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The User Activity Log WordPress plugin prior to 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.

Vulnerable Product Search on Vulmon Subscribe to Product

solwininfotech user activity log