The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2023-09-04T11:26:56.095Z

Updated: 2023-09-15T18:08:29.798Z

Reserved: 2023-08-09T08:21:12.900Z


Link: CVE-2023-4269

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-09-04T12:15:10.470

Modified: 2023-11-07T04:22:22.850


Link: CVE-2023-4269

JSON object: View

cve-icon Redhat Information

No data.

CWE