{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-42673",
        "assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
        "state": "PUBLISHED",
        "assignerShortName": "Patchstack",
        "dateReserved": "2026-04-29T09:04:52.624Z",
        "datePublished": "2026-06-01T15:24:05.488Z",
        "dateUpdated": "2026-06-01T17:06:40.773Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
                "shortName": "Patchstack",
                "dateUpdated": "2026-06-01T15:24:05.488Z"
            },
            "title": "WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin <= 3.3.6 - Sensitive Data Exposure vulnerability",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-201",
                            "description": "CWE-201 Insertion of Sensitive Information Into Sent Data",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-37",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-37 Retrieve Embedded Sensitive Data"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Logtivity Activity Logs",
                    "product": "Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity",
                    "collectionURL": "https://wordpress.org/plugins",
                    "packageName": "logtivity",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "n/a",
                            "lessThanOrEqual": "3.3.6",
                            "changes": [
                                {
                                    "at": "3.3.7",
                                    "status": "unaffected"
                                }
                            ],
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data.\n\nThis issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data.<p>This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.</p>"
                        }
                    ]
                }
            ],
            "tags": [
                "x_open-source"
            ],
            "references": [
                {
                    "url": "https://patchstack.com/database/wordpress/plugin/logtivity/vulnerability/wordpress-activity-logs-user-activity-tracking-multisite-activity-log-from-logtivity-plugin-3-3-6-sensitive-data-exposure-vulnerability?_s_id=cve",
                    "tags": [
                        "vdb-entry"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "NONE",
                        "availabilityImpact": "NONE",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.5,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Update the WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin to the latest available version (at least 3.3.7).",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Update the WordPress Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity Plugin to the latest available version (at least 3.3.7)."
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Peng Zhou | Patchstack Bug Bounty Program",
                    "user": "00000000-0000-4000-9000-000000000000",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "EXTERNAL"
            },
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-06-01T17:01:50.368753Z",
                                "id": "CVE-2026-42673",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "yes"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-06-01T17:06:40.773Z"
                }
            }
        ]
    }
}