CVE-2026-13736 PUBLISHED

NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API

Assigner: WPScan
Reserved: 29.06.2026 Published: 21.08.2026 Updated: 21.08.2026

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.

Product Status

Vendor Unknown
Product NewPath WildApricotPress Add-on
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Huynh Kien Minh finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE