CVE-2025-0767: WP Activity Log 5.3.2 - Insecure deserialization
Published Feb 27, 2025
·Updated
WP Activity Log 5.3.2 was found to be vulnerable. Unvalidated user input is used directly in an unserialize function in myapp/classes/Writers/class-csv-writer.php.
Affected Software
2 affected components
WP Activity Log WP Activity Log
Melapress Wp Activity Log Wordpress=5.3.2
Event History
Feb 27, 2025
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-0767?
CVE-2025-0767 has been rated as a high severity vulnerability due to its potential exploitation of unserialized user input.
2
How do I fix CVE-2025-0767?
To fix CVE-2025-0767, update the WP Activity Log plugin to the latest version where the vulnerability has been addressed.
3
What impact does CVE-2025-0767 have on my website's security?
CVE-2025-0767 allows attackers to exploit unvalidated user input, potentially leading to remote code execution or data manipulation.
4
Which versions of WP Activity Log are affected by CVE-2025-0767?
CVE-2025-0767 affects WP Activity Log versions prior to 5.3.2.
5
Is there a workaround for CVE-2025-0767 if I cannot update immediately?
As a temporary workaround for CVE-2025-0767, remove or disable the WP Activity Log plugin until you can update to a secure version.