The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)
History

Wed, 28 Jan 2026 06:15:00 +0000

Type Values Removed Values Added
Description The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)
Title User Activity Log <= 2.2 - Unauthenticated Limited Arbitrary Option Update
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-01-28T06:00:03.740Z

Reserved: 2025-11-20T08:38:24.493Z

Link: CVE-2025-13471

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-28T06:15:47.477

Modified: 2026-01-28T06:15:47.477

Link: CVE-2025-13471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.