The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
User_activity_log | Solwininfotech | * | 2.3.4 (excluding) |