Description
WordPress Plugin User Activity is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently spoof the IP address of the request. WordPress Plugin User Activity version 1.0.1 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
WebLogic Other Vulnerability (CVE-2020-10673)
WordPress Plugin YITH WooCommerce Stripe Security Bypass (2.0.1)
WordPress Plugin WooCommerce-Store Exporter Privilege Escalation (1.8.3)
MySQL CVE-2012-3173 Vulnerability (CVE-2012-3173)
WordPress Plugin Mass Pages/Posts Creator Cross-Site Scripting (1.2.2)