Description
The User Activity Log plugin is vulnerable to a limited options update in versions up to, and including, 2.2. The failed-login handler 'ual_shook_wp_login_failed' lacks a capability check and writes failed usernames directly into update_option() calls. This makes it possible for unauthenticated attackers to push select site options from 0 to a non-zero value, allowing them to reopen registration or corrupt options like 'wp_user_roles', breaking wp-admin access. CVE-2025-13471 appears to be a duplicate of this CVE.
INFO
Published Date :
2026-01-07T08:21:49.731Z
Last Modified :
2026-04-08T16:42:09.188Z
Source :
Wordfence
AFFECTED PRODUCTS
The following products are affected by CVE-2025-11877 vulnerability.
| Vendors | Products |
|---|---|
| Solwininfotech |
|
| Wordpress |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-11877.