CVE-2025-3436 | Activity Logging Plugin up to 2.7 on WordPress orderby sql injection
A vulnerability classified as critical was found in Activity Logging Plugin up to 2.7 on WordPress. This vulnerability affects unknown code. The manipulation of the argument orderby leads to sql injection.
This vulnerability was named CVE-2025-3436. The attack can be initiated remotely. There is no exploit available.