Security Research

CVE-2024-10793 WP Activity Log Stored XSS to RCE: Unsanitized Writes to the Admin Render Plane

#Vulnerability Analysis#Code Audit#Web Security
Dark dossier of WordPress admin log panel and injected script flame

WP Activity Log treats the admin’s “activity log” panel as a trusted render plane, but leaves the write path unsanitized — an attacker injects HTML through admin-ajax, and any admin who opens the panel is compromised. With stolen nonce credentials plus a plugin upload, the chain from anonymous POST to RCE is complete.

Unlock to view this content.