
CVE-2026-1671 The Activity Log for WordPress plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the winter_activity_log_action() f… https://www.cve.org/CVERecord?id=CVE-2026-1671
Post summary
A newly disclosed CVE (CVE-2026-1671) affects the WordPress Activity Log plugin, allowing unauthorized data access because of a missing capability check in the winter_activity_log_action function.

