Skip to main content

Vendor/product archive

dev4press / coreactivity CVEs

Beta · best-effort

2 CVEs tagged to dev4press / coreactivity0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2024-0852

Published May 15, 2025

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated use…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-0868

Published Apr 17, 2024

The coreActivity: Activity Logging plugin for WordPress plugin before 2.1 retrieved IP addresses of requests via headers such X-FORWARDED to log them, allowing users to spoof them…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1