Known vulnerabilities in Stream – Activity Log & Audit Trail
Real-time activity log and audit log for WordPress. Track every user action — logins, edits, plugin & settings changes — and get alerts.
8Reported vulnerabilities
8.8Highest CVSS score
4.3.0Latest version
80,000+Active installs
What to do now
Update Stream – Activity Log & Audit Trail to 4.2.1 or later.
8 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2021-24772 | High | 1.5% | Before 3.8.2 | 3.8.2 |
November 17, 2021 |
| CVE-2022-4384 | Medium | 0.9% | Before 3.9.2 | 3.9.2 |
February 6, 2023 |
| CVE-2024-7423 | High | 0.3% | Before 4.0.2 | 4.0.2 |
September 13, 2024 |
| WF-ecd68933-e808-4816-b9d2-7491194f2347 | High | — | 3.0.5 and earlier | 3.0.6 |
May 31, 2016 |
| CVE-2026-11907 | Medium | 0.2% | 0 to 4.2.0 (inclusive) | 4.2.1 |
August 7, 2026 |
| CVE-2024-13879 | Medium | 0.3% | 4.0.2 and earlier | 4.1.0 |
February 14, 2025 |
| CVE-2022-43450 | Medium | 0.7% | Before 3.9.3 | 3.9.3 |
April 25, 2023 |
| CVE-2022-43490 | Medium | 0.3% | 3.9.2 and earlier | 3.9.3 |
April 18, 2023 |