← WordPress Vulnerabilities
WordPress security by component

Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity

Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity records WordPress user activity and administrative events, including activity across multisite networks.

Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity (logtivity) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Jun 01, 2026; the highest published CVSS base score is 7.5.

Plugin slug: logtivity

CVE-2026-42673: Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: A security weakness

Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.3.6.

PublishedJun 01, 2026
Known safe version3.3.7
Published vulnerabilities for logtivity
Safe version
Jun 01, 2026 CVE-2026-42673
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: A security weakness
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is n/a through 3.3.6.
3.3.7
CVE7.5
NVDPending
May 09, 2026 CVE-2026-8198
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: Privilege escalation or authentication bypass
Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 3.3.6.
See mitigation notes
CVE5.3
NVDPending