CVE Database
/

CVE-2023-5167

Back to search

CVE-2023-5167

Published: Oct 16, 2023

Modified: Apr 23, 2025

PUBLISHED

Description

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

VendorProductVersions

Unknown

user-activity-log-pro

affected
0 - < 2.3.4

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now