Sceawere

Vulnerability Detail

CVE-2026-62085UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP Activity Log SQL Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.6
Creation Date
3h ago
Vendor
Melapress
Product
WP Activity Log
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

Administrator SQL Injection in WP Activity Log <= 5.6.6 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.6",
  "pubDate": "2026-09-30T13:17:19.740Z",
  "pubdate": "2026-09-30T13:17:19.740Z",
  "executiveSummary": "The WP Activity Log plugin for WordPress, in versions 5.6.6 and below, is susceptible to a SQL injection vulnerability. This flaw allows an authenticated administrator to inject arbitrary SQL commands through improper sanitization of user-supplied input.\nThe vulnerability type is categorized as Improper Neutralization of Special Elements used in an SQL Command (SQL Injection).\nThe impact of this vulnerability is severe, potentially allowing an attacker with administrative privileges to gain unauthorized access to the underlying database, retrieve sensitive information, modify data, or execute administrative database operations.\nExploitation requires administrative-level access, meaning an attacker must already have high-privileged credentials to interact with the vulnerable component.\nThis represents a significant risk to the integrity and confidentiality of the WordPress database. Once access is achieved, the attacker can leverage the SQL injection to bypass application-level restrictions or escalate privileges within the database management system.\nThe attack is performed via the administrative interface, and successful exploitation depends on the application's failure to adequately parameterize or escape input handled by the plugin's query construction logic.",
  "technicalDetails": "The root cause of this vulnerability lies in the insecure handling of administrative inputs within the WP Activity Log plugin, where user-supplied data is concatenated directly into SQL query strings without sufficient sanitization or the use of prepared statements.\nIn versions 5.6.6 and lower, the plugin fails to properly validate inputs destined for database queries associated with activity log filtering or reporting functions. When a privileged user (administrator) interacts with specific plugin settings or report generation tools, the input is passed to an internal database query function.\nThe attack flow proceeds as follows: An authenticated administrator crafts a malicious request containing SQL syntax characters (e.g., single quotes, comment indicators, or UNION SELECT statements) within an input field processed by the plugin. Because the backend does not enforce parameterized queries, the database engine interprets the malicious input as part of the intended SQL command, effectively altering the logic of the query.\nThe vulnerability allows for blind or error-based SQL injection techniques, enabling the attacker to extract data from the wp_options, wp_users, or other critical tables. By manipulating the query structure, an attacker can extract password hashes, session tokens, or other administrative credentials stored in the database.\nFurthermore, the vulnerability allows for post-exploitation impacts such as data exfiltration, database structure discovery, and in some database configurations, potential arbitrary command execution if the database user permissions are overly permissive. The specific vulnerable component is likely contained within the plugin's reporting or filtering module which processes administrative parameters during the construction of complex SELECT queries.\nAuthentication is a prerequisite, as the vulnerable functions are restricted to the administrative dashboard. However, once authenticated, the attacker faces no further barriers to manipulating the database structure. This is a critical security concern as it implies that a compromised or malicious administrative account can gain full control over the database, effectively bypassing the plugin's intended logging and monitoring security posture."
}
CVE-2026-62085: WP Activity Log SQL Injection (HIGH Severity, CVSS: 7.6) | Sceawere