CVE-2026-8198Disclosure

MEDIUMCVSS 5.3 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Information Disclosure in versions up to, and including, 3.3.6. This is due to a logic flaw in the verifyAuthorization method where requests without an Authorization header skip Bearer token validation and fall through to an unconditional return true statement, bypassing all authentication checks. This makes it possible for unauthenticated attackers to access the /wp-json/logtivity/v1/options REST API endpoint and retrieve all plugin configuration options, including the logtivity_site_api_key which can be used to impersonate the site in API calls to the Logtivity service.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-05-09); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-09: 3Mentions · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-10: 1Active Exploitation · 2026-05-10: 1Technical Details · 2026-05-09: 305-0905-10
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-093
Disclosure2General1
2026-05-101
Active Exploitation1
Full discourse4 posts
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting logtivity Activity Logs, User Activity Tracking, Multisite Activity Log Plugin (CVE-2026-8198) https://vuldb.com/vuln/362456/cti

    Post summary

    The statement reports ongoing offensive activity against the Multisite Activity Log Plugin (CVE-2026-8198), indicating that the vulnerability is being actively exploited, though no solutions or technical details are provided.

    0000062
    2.1K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🔓 WordPress Logtivity plugin (≤ 3.3.6) vulnerable to auth bypass leading to information disclosure due to flawed authorization checks. #CVE #WordPress #Infosec https://nvd.nist.gov/vuln/detail/CVE-2026-8198

    Post summary

    A disclosure alert notes that WordPress Logtivity plugin (versions up to 3.3.6) suffers from an authentication bypass that can expose sensitive information, caused by improper authorization checks.

    000005
    1.3K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-8198 The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Information Disclosure i… https://www.cve.org/CVERecord?id=CVE-2026-8198

    Post summary

    The excerpt merely states that CVE-2026-8198 affects the Logtivity WordPress plugin with an authentication bypass leading to information disclosure, with no further technical details, PoC, exploit, or patch information.

    0000051
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-8198 Authentication Bypass and Information Disclosure in Logtivity WordPress Plugin Versions Up to 3.3.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-8198

    Post summary

    The snippet announces a new CVE (Authentication Bypass and Information Disclosure) affecting Logtivity WordPress Plugin up to 3.3.6, providing basic technical details but no PoC, exploit code, or patch information.

    0000057
    4.0K followersView on X

Explore more