CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 4.3. It affects WordPress. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-4269
Severity
MEDIUM
CVSS
4.3
EPSS
0.43%
WordPress
Original NVD Description
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its activity logs, allowing any authenticated users, such as subscriber to perform such action and retrieve PII such as email addresses.
Related CVEs
Other vulnerabilities affecting the same vendor(s)