LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7635 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: May 13, 2026

coreActivity: Activity Logging for WordPress - Insecure Deserialization

Published: May 13, 2026Updated: May 13, 2026Remote Exploitable

Overview

coreActivity: Activity Logging for WordPress plugin <= 3.0 contains a PHP Object Injection caused by improper validation of User-Agent HTTP header serialization, letting unauthenticated attackers cause persistent denial of service by triggering fatal errors when admins view logs.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Unauthenticated attackers can cause persistent denial of service, blocking administrator access to the Logs page.

Mitigation

Update to the latest version beyond 3.0 where this issue is fixed.

Details

CVE ID
CVE-2026-7635
Severity
High
CVSS Score
8.1
Type
insecure_deserialization
Status
rejected

CWE

  • CWE-502

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H