S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Mar 11, 2026

CVE-2023-6030 Scanner

CVE-2023-6030 Scanner - SQL Injection vulnerability in LogDash Activity Log plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.8k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-6030
5.4
CVSSmedium
Exploitable remotely over the internet · low-privilege account sufficient.

The LogDash Activity Log WordPress plugin before 1.1.4 hooks the wp_login_failed function (from src/Hooks/Users.php) in order to log failed login attempts to the database but it doesn't escape the username when it perform some SQL request leading to a SQL injection vulnerability which can be exploited using time-based technique by unauthenticated attacker

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
LogDash Activity Log
AFFECTED< 1.1.4SAFE ✓≥ 1.1.4
Updated Aug 22, 2026View on NVD →
Detail

The LogDash Activity Log plugin for WordPress is widely used by administrators to track user activities within their websites, providing insights for security and user behavior analysis. It is favored for its detailed logs and easy integration with existing WordPress installations. This plugin is used extensively in environments where monitoring of user actions is critical, such as e-commerce websites, membership sites, and blogs. Companies and individual developers use this plugin to ensure user actions are transparent and recorded for both security and analysis purposes. Despite its usefulness, inadequate handling of input parameters in versions up to and including 1.1.3 has led to identifying security vulnerabilities. As a result, the plugin plays a pivotal role but also requires attention to updates for maintaining security.

The SQL Injection vulnerability in the LogDash Activity Log plugin arises from improper handling and escaping of user-supplied input, specifically through the username parameter. SQL Injection is a type of security exploit where the attacker adds structured query language (SQL) code to a web form input box to gain unauthorized access or retrieve sensitive data. In this case, unauthenticated attackers could potentially execute arbitrary SQL queries that manipulate the database's structure or content. The impact of this vulnerability is significant in environments where this plugin is used to log critical data, making all data records and possibly more accessible to an attacker. Given the severity of this type of attack, timely upgrades and patches are crucial.

Technical details about this vulnerability indicate that it affects all versions of the plugin up to 1.1.3, by taking advantage of the insufficient escaping process of the username parameter. The vulnerability resides within the SQL query handling processes where user inputs are appended without adequate sanitization. Specifically, the plugin fails to adequately prepare the existing SQL query, allowing malicious SQL statements to be appended and executed if an attacker inserts crafted input data. Internally, this leads to exposure of significant control over the database to any unauthenticated user over the internet.

If exploited, this SQL Injection vulnerability could allow attackers to perform any operation on the database, which includes reading sensitive data, modifying records, deleting data, or even escalating their own privileges. The ability to tamper with the database could also lead to unauthorized access to administrative functions, compromise data integrity, and privacy breaches affecting potentially all users of a compromised WordPress site using this plugin. Such exploitation could lead to reputation damage and significant losses in user trust.

REFERENCES

Solution Advice
  • Upgrade the LogDash Activity Log plugin to version 1.1.4 or later to mitigate the SQL Injection vulnerability.
  • Regularly review and update plugins and themes to ensure the latest security patches are applied.
  • Implement additional security plugins or services that monitor and block SQL Injection attempts on your WordPress site.
  • Conduct regular security audits and penetration testing to identify potential vulnerabilities in your WordPress installations.
  • Educate users and administrators on secure coding practices to prevent future vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.