PatchSiren cyber security CVE debrief
CVE-2026-42673 Logtivity Activity Logs CVE debrief
A HIGH severity vulnerability (CVSS 7.5) in the Logtivity Activity Logs WordPress plugin allows unauthenticated remote attackers to retrieve embedded sensitive data. The plugin fails to prevent insertion of sensitive information into sent data (CWE-201), exposing confidential material in outbound responses. Affected versions span from initial release through 3.3.6. The CVE was published on 2026-06-01 and carries a Deferred status in NVD. No known exploitation in ransomware campaigns has been documented.
- Vendor
- Logtivity Activity Logs
- Product
- Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-01
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-06-01
- Advisory updated
- 2026-07-22
Who should care
WordPress site administrators using the Logtivity Activity Logs plugin, security teams monitoring WordPress environments, and compliance officers responsible for data protection in content management systems.
Technical summary
The Logtivity Activity Logs plugin for WordPress (versions through 3.3.6) contains an Insertion of Sensitive Information Into Sent Data vulnerability (CWE-201). The plugin captures and transmits activity log data without adequately filtering or protecting embedded sensitive information. An unauthenticated remote attacker can exploit this weakness to retrieve confidential data from responses sent by the plugin. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network accessibility, low attack complexity, no required privileges or user interaction, and high impact to confidentiality with no impact to integrity or availability.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Logtivity Activity Logs plugin to a version newer than 3.3.6 as soon as a patched release becomes available
- Review plugin settings and logged data fields to identify any sensitive information that may have been captured or transmitted
- Audit WordPress site access logs for unusual unauthenticated requests targeting Logtivity endpoints around and after 2026-06-01
- Consider temporarily disabling the plugin if no patch is available and the functionality is not critical
- Implement Web Application Firewall rules to restrict access to Logtivity API endpoints if feasible
- Review and rotate any credentials or tokens that may have been logged by the plugin
Evidence notes
Vulnerability identified via Patchstack audit. CVSS vector confirms network attack vector with low complexity, no privileges required, no user interaction, and high confidentiality impact with no integrity or availability impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-42673 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-42673
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-42673 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-42673
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.