PT-2026-34864 · Liaison · Liaison Site Prober

Itthidej Aramsri

·

Published

2026-04-24

·

Updated

2026-04-24

·

CVE-2026-3569

CVSS v3.1

5.3

Medium

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The Liaison Site Prober plugin for WordPress is vulnerable to Information Exposure in all versions up to and including 1.2.1 via the /wp-json/site-prober/v1/logs REST API endpoint. The permissions read() permission callback unconditionally returns true (via return true()) instead of checking for appropriate capabilities. This makes it possible for unauthenticated attackers to retrieve sensitive audit log data including IP addresses, user IDs, usernames, login/logout events, failed login attempts, and detailed activity descriptions.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3569

Affected Products

Liaison Site Prober