Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2024-0852

The coreActivity: Activity Logging for WordPress plugin before 1.8.1 does not escape some request data when outputting it back in the admin dashboard, allowing unauthenticated users to perform Stored XSS attack against high privilege users such as admin

  • Published: May 15, 2025
  • Updated: Nov 14, 2025
  • CVE: CVE-2024-0852
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 8.8
  • AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H