CVE-2026-54806

CRITICAL LAB

WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-54806. PoCs published by joshuavanderpoll.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-54806, an unauthenticated PHP object injection vulnerability in WP Activity Log <= 5.6.3.1. The exploit leverages the User-Agent header to inject a serialized payload that executes when an admin visits the WordPress dashboard.

Description

Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions.

Exploits (1)

github WORKING POC 1 stars
by joshuavanderpoll · pythonpoc
https://github.com/joshuavanderpoll/CVE-2026-54806

This repository contains a functional exploit for CVE-2026-54806, an unauthenticated PHP object injection vulnerability in WP Activity Log <= 5.6.3.1. The exploit leverages the User-Agent header to inject a serialized payload that executes when an admin visits the WordPress dashboard.

Classification
Working Poc 100%
Attack Type
Deserialization
Complexity
Moderate
Reliability
Reliable
Target: WP Activity Log (wp-security-audit-log) <= 5.6.3.1
No auth needed
Prerequisites: WordPress 6.4.0-6.4.1 · WP Activity Log <= 5.6.3.1 · Admin dashboard access to trigger payload
mistral-large-3 · analyzed Jun 22, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0070
EPSS Percentile 49.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:6.4.1-php8.3-apache
docker pull wordpress:cli-php8.3
docker pull curlimages/curl:latest

Details

CWE
CWE-502
Status published
Products (1)
Melapress/WP Activity Log < 5.6.3.1
Published Jun 17, 2026
Tracked Since Jun 17, 2026