PT-2025-21372 · WordPress · Logdash Activity Log

Nicolas Surribas

·

Publicado

2025-05-15

·

Atualizado

2026-03-11

·

CVE-2023-6030

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: LogDash Activity Log WordPress plugin versions prior to 1.1.4
Description: The issue concerns a SQL injection vulnerability. It occurs because the plugin does not properly escape the username when performing SQL requests, specifically when logging failed login attempts through the wp login failed function. This can be exploited by an unauthenticated attacker using time-based techniques.
Recommendations: For versions prior to 1.1.4, update to version 1.1.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the wp login failed function until a patch is applied. Avoid using the username variable in affected SQL requests until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-6030

Produtos afetados

Logdash Activity Log