Junglewise Threat Intelligence

CVE-2026-84759: Elementor Activity Log CSRF vulnerability

CVE-2026-84759 · Severity: high · CVSS 7.1 · Published 2026-09-02

Vendors: Elementor.

Executive brief

The Activity Log plugin for WordPress records user actions and activity on WordPress sites. An unauthenticated attacker can exploit a cross-site request forgery (CSRF) flaw to trick logged-in site administrators or users into performing unintended actions, such as modifying settings or deleting logs, without their knowledge or consent.

Technical details

The Activity Log plugin versions 2.13.1 and earlier contain a CSRF vulnerability due to insufficient token validation or missing CSRF protection mechanisms. Although the vulnerability requires user interaction—a privileged user must click a malicious link or visit a crafted page—an unauthenticated attacker can craft these payloads and deliver them via email, social media, or compromised websites. The attack allows unauthorized actions to be performed in the context of the victim's authenticated session. The vulnerability has been patched in version 2.14.0.

Affected products

  • Elementor Activity Log <= 2.13.1

Timeline

  • 2026-09-02: disclosed: Vulnerability published by Patchstack
  • 2026-09-02: patched: Fixed in version 2.14.0

References