WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://fluidattacks.com/advisories/skims-9/ | third party advisory |
https://co.wordpress.org/plugins/wp-security-audit-log/ | product |