Junglewise Threat Intelligence

CVE-2026-54806: Melapress WP Activity Log PHP object injection

CVE-2026-54806 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Melapress WP Activity Log. Vendors: Melapress.

Executive brief

WP Activity Log is a popular WordPress plugin used to track and log user activity on websites. A critical security flaw allows unauthenticated attackers to inject malicious code into the site. If exploited, this could lead to full site takeover, data theft, or complete service disruption.

Technical details

The WP Activity Log plugin for WordPress is vulnerable to PHP Object Injection in versions up to and including 5.6.3.1. This issue stems from the insecure deserialization of untrusted data (CWE-502). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application. If a suitable Property-Oriented Programming (POP) chain is present on the server, the attacker can achieve remote code execution, perform SQL injection, or access sensitive files. The vulnerability is resolved in version 5.6.4.

Affected products

  • Melapress WP Activity Log <= 5.6.3.1

Timeline

  • 2026-05-21: other: Reported by researcher daroo
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date
  • 2026-06-17: patched: Patch confirmed available in version 5.6.4

References

Related threats