CVE-2025-13471

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/01/2026
Last modified:
29/01/2026

Description

The User Activity Log WordPress plugin through 2.2 does not properly handle failed login attempts in some cases, allowing unauthenticated users to set arbitrary options to 1 (for example to enable User Registration when it has been turned off)