Junglewise Threat Intelligence

CVE-2026-65512: Melapress WP Activity Log CSRF in plugin settings

CVE-2026-65512 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Technologies: Melapress WP Activity Log. Vendors: Melapress.

Executive brief

WP Activity Log is a popular WordPress plugin used to track and log user activity on a website for security and auditing purposes. A security vulnerability exists where an attacker can trick a site administrator into performing unintended actions, such as changing plugin settings or deleting logs, by getting them to click a malicious link. While this requires the administrator to be logged in and interact with a specific link, it could lead to unauthorized changes to the site's audit trail.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the WP Activity Log plugin for WordPress due to insufficient nonce validation on sensitive actions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it (e.g., via phishing or a malicious site). Successful exploitation allows the attacker to perform actions with the privileges of the victim, such as modifying plugin configurations or audit logs. The issue is fixed in version 5.6.5.

Affected products

  • Melapress WP Activity Log <= 5.6.4

Timeline

  • 2026-07-02: disclosed: Reported by Levon Balyan
  • 2026-07-23: advisory: Published by Patchstack and NVD
  • 2026-07-23: patched: Version 5.6.5 released to address the issue

References

Related threats