Description
WordPress Plugin WP Activity Log is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently run the install wizard and configure a large set of options, if the wizard hasn't been completed in the first place. WordPress Plugin WP Activity Log version 4.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.2 or latest
References
https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-wp-security-audit-log-plugin/
https://www.wpsecurityauditlog.com/support-documentation/plugin-changelog/