Description
The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker
Published: 2025-05-15
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-58288 The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker
History

Wed, 11 Jun 2025 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Deryckoe
Deryckoe logdash Activity Log
Weaknesses CWE-89
CPEs cpe:2.3:a:deryckoe:logdash_activity_log:*:*:*:*:*:wordpress:*:*
Vendors & Products Deryckoe
Deryckoe logdash Activity Log

Fri, 16 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker
Title LogDash Activity Log < 1.1.4 - Unauthenticated SQLi
References

Subscriptions

Deryckoe Logdash Activity Log
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2025-05-16T18:30:18.530Z

Reserved: 2023-11-08T12:00:14.030Z

Link: CVE-2023-6030

cve-icon Vulnrichment

Updated: 2025-05-16T18:30:07.344Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:28.817

Modified: 2025-06-11T19:24:00.583

Link: CVE-2023-6030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses