Security Research

CVE-2024-10793 WP Activity Log: Stored XSS to RCE in the Audit Page

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of WordPress audit log page and injected script path

WP Activity Log writes user behavior into the log page with zero sanitization. Once the stored XSS fires, the attacker grabs the admin nonce and uploads a PHP webshell — the entire chain goes from a single log entry all the way to RCE.

Unlock to view this content.