Known vulnerabilities in coreActivity: Activity Logging for WordPress
Monitor and log all kinds of activity happening on the WordPress website, with fine control over events to log, detailed log and events panels...
4Reported vulnerabilities
8.8Highest CVSS score
3.1.1Latest version
10+Active installs
What to do now
Update coreActivity: Activity Logging for WordPress to 3.1 or later.
4 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2024-0852 | High | 0.7% | Before 1.8.1 | 1.8.1 |
May 15, 2025 |
| CVE-2024-0868 | Medium | 0.5% | Before 2.1 | 2.1 |
April 17, 2024 |
| CVE-2026-7635 | High | 0.5% | 0 to 3.0 (inclusive) | 3.1 |
May 13, 2026 |
| CVE-2025-3436 | Medium | 0.4% | 0 to 2.7 (inclusive) | 2.7.1 |
April 8, 2025 |