The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view potentially sensitive information (e.g., the password of a higher level user, such as an administrator) contained in the exposed log files.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Feb 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view potentially sensitive information (e.g., the password of a higher level user, such as an administrator) contained in the exposed log files. | |
| Title | Activity Log for WordPress <= 1.2.8 - Missing Authorization to Sensitive Information Exposure via Log File | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-12T14:15:56.801Z
Reserved: 2026-01-30T00:45:01.261Z
Link: CVE-2026-1671
Updated: 2026-02-12T14:15:36.226Z
Status : Awaiting Analysis
Published: 2026-02-12T13:15:49.880
Modified: 2026-02-12T15:10:37.307
Link: CVE-2026-1671
No data.
OpenCVE Enrichment
No data.