CVE-2026-54806
Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.
- Affected products
- Wp Activity Log, Wp Security Audit Log
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-502
- NVD status
- Deferred
- Published
- 2026-06-17
- Attack patterns
- CAPEC-586
Fix
Update the WordPress WP Activity Log Plugin to the latest available version (at least 5.6.4).
CVE-2026-54806 at NVD
2 known exploits for CVE-2026-54806
Proof-of-concept code and exploit modules indexed by Sploitus