Description
WordPress Plugin WP Activity Log is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently run the install wizard and configure a large set of options, if the wizard hasn't been completed in the first place. WordPress Plugin WP Activity Log version 4.0.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.0.2 or latest
References
https://blog.nintechnet.com/vulnerabilities-fixed-in-wordpress-wp-security-audit-log-plugin/
https://melapress.com/support/kb/wp-activity-log-plugin-changelog/
Related Vulnerabilities
WordPress Plugin WooCommerce OpenPOS SQL Injection (6.4.4)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.13)
WordPress Plugin Image Rotator Cross-Site Scripting (1.0)
Artifactory Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2016-10036)
WordPress Plugin Smash Balloon Social Post Feed Unspecified Vulnerability (2.4.2)