CVE-2025-13471Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-28: 2Technical Details · 2026-01-28: 201-28
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13471 Unauthenticated Option Manipulation in User Activity Log WordPress Plugin https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13471

    Post summary

    This post announces CVE-2025-13471, an unauthenticated option manipulation flaw in the User Activity Log WordPress plugin, and links to a vulnerability detail page.

    0000062
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13471 The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary optio… https://www.cve.org/CVERecord?id=CVE-2025-13471

    Post summary

    The tweet discloses that the User Activity Log WordPress plugin before version 2.2 has a flaw letting unauthenticated users set arbitrary options via failed login attempts.

    00000225
    56.5K followersView on X

Explore more