CVE-2026-3569
Last modified
CVE-2026-3569 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for appropriate capabilities. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions_read() permission callback unconditionally returns true (via __return_true()) instead of checking for appropriate capabilities. This makes it possible for unauthenticated attackers to retrieve sensitive audit log data including IP addresses, user IDs, usernames, login/logout events, failed login attempts, and detailed activity descriptions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-3569?
How severe is CVE-2026-3569?
How do I fix CVE-2026-3569?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-35674OpenClaw before 2026.5.18 contains a scope bypass vulnerabil…8.8
- CVE-2026-35675phpMyFAQ before 4.1.3 contains an authentication bypass vuln…8.8
- CVE-2026-35676phpMyFAQ before 4.1.3 contains an unauthenticated password r…8.8
- CVE-2026-35679Zcash zcashd before 6.12.0 allows invalid transactions to be…3.5
- CVE-2026-3568The MStore API plugin for WordPress is vulnerable to Insecu…4.3
- CVE-2026-35682Anviz CX2 Lite is vulnerable to an authenticated command inj…8.8
- CVE-2026-3570The Smarter Analytics plugin for WordPress is vulnerable to …5.3
- CVE-2026-3571The Pie Register – User Registration, Profiles & Content Res…6.5
- CVE-2026-35716A stack-based buffer overflow in the motion_privacy.cgi bina…6.3
- CVE-2026-35717A stack-based buffer overflow in the export_language.cgi bin…6.3
- CVE-2026-35718A path traversal vulnerability in the /admin/downloadMedias.…6.5
- CVE-2026-3572The iTracker360 plugin for WordPress is vulnerable to Cross-…6.1
Are you affected by CVE-2026-3569?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
