Sploitus

CVE-2026-54806

2 known exploits for CVE-2026-54806

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

CVSS 3.1
9.8 CRITICAL
EPSS
0.7% (51th percentile)
Weakness
CWE-502
NVD status
Deferred
Published
2026-06-17
Attack patterns
CAPEC-586

Fix

Update the WordPress WP Activity Log Plugin to the latest available version (at least 5.6.4).

CVE-2026-54806 at NVD
Authoritative description, scoring and affected products

2 known exploits for CVE-2026-54806

Proof-of-concept code and exploit modules indexed by Sploitus