Junglewise Threat Intelligence

CVE-2026-42673: Logtivity WordPress Plugin sensitive data exposure in activity logs

CVE-2026-42673 · Severity: high · CVSS 7.5 · Published 2026-06-01

Executive brief

A security vulnerability exists in the Logtivity plugin for WordPress, which is used to track user activity and maintain audit logs across websites. This flaw allows sensitive information to be inadvertently included in data sent by the plugin, potentially exposing private details to unauthorized individuals. An attacker could exploit this to gain access to internal system data, which could lead to further compromises of the website or its users.

Technical details

The Logtivity plugin (versions up to and including 3.3.6) suffers from a CWE-201 (Insertion of Sensitive Information Into Sent Data) vulnerability. This flaw occurs when the plugin's activity logging and tracking mechanisms include sensitive data in outgoing transmissions that should remain private. An unauthenticated attacker can exploit this over the network to retrieve embedded sensitive data without any user interaction. This exposure can provide the necessary information to facilitate more complex attacks against the WordPress environment. The issue is resolved in version 3.3.7.

Affected products

  • Logtivity Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6

Timeline

  • 2026-04-14: other: Reported by Peng Zhou
  • 2026-05-14: advisory: Patchstack advisory published
  • 2026-06-01: disclosed: CVE published to NVD

References

Related threats