Known vulnerabilities in Activity Log for WordPress
Detailed WordPress Activity Log with user request tracking, instant logout, request restrictions, locking, blocking, alerts, and more.
3Reported vulnerabilities
6.5Highest CVSS score
1.2.9Latest version
50+Active installs
What to do now
Update Activity Log for WordPress to 1.2.8 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-1671 | Medium | 0.3% | 0 to 1.2.8 (inclusive) | 1.2.9 |
February 12, 2026 |
| CVE-2026-24987 | Medium | 0.4% | 1.2.7 and earlier | 1.2.8 |
March 17, 2026 |
| CVE-2025-24982 | Medium | 0.2% | 1.2.4 and earlier | 1.2.5 |
February 4, 2025 |