Activity Log WordPress Plugin Stored Cross Site Scripting (XSS)
Activity Log is a WordPress plugin which tracks site activity. It has more than 70.000 active installations. Version 2.4.0 (and possibly the previous ones) are affected by several Stored XSS vulnerabilities. To successfully exploit this vulnerability, an attacker would have to perform any of the following: Create/edit/draft/publish/trash/untrash a post with JavaScript in the title, Create/edit/trash/untrash/mark_as_spam/unmark_as_spam a comment on a post with JavaScript in the title, Add/edit/delete an attachment with JavaScript in the attachment title. Regular website visitors will not have the capability to do any of these, however, possible threa actors are: Administrators, Editors, Authors, Contributors.