CVE-2026-1671 | Activity Log Plugin up to 1.2.8 on WordPress winter_activity_log_action authorization
A vulnerability was found in Activity Log Plugin up to 1.2.8 on WordPress. It has been rated as problematic. Affected is the function winter_activity_log_action. This manipulation causes missing authorization.
This vulnerability is handled as CVE-2026-1671. The attack can be initiated remotely. There is not any exploit available.