User Activity Log <= 2.2 - Unauthenticated Limited Options Update via Failed Login
Vulnerability Description
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push select site options from 0 to a non-zero value, allowing them to reopen registration or corrupt options like 'wp_user_roles', breaking wp-admin access. CVE-2025-13471 appears to be a duplicate of this CVE.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11877
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Angus Girvan
References
More from solwininfotech
View All →Affected Vendor
solwininfotech
View all reports →