Files
CVEs-PoC/2023/CVE-2023-5167.md
T
2025-09-29 21:09:30 +02:00

770 B

CVE-2023-5167

Description

The User Activity Log Pro WordPress plugin before 2.3.4 does not properly escape recorded User-Agents in the user activity logs dashboard, which may allow visitors to conduct Stored Cross-Site Scripting attacks.

POC

Reference

Github