PT-2026-79298 · Newpath · Wildapricotpress Add-On

CVE-2026-13736

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions NewPath WildApricotPress Add-on versions prior to 1.0.1
Description The NewPath WildApricotPress Add-on WordPress plugin fails to enforce privacy restrictions for members-only fields on an unauthenticated REST route. This allows anonymous visitors to access sensitive personally identifiable information (PII), specifically member email addresses and phone numbers, which are intended to be visible only to authenticated members.
Recommendations Update the NewPath WildApricotPress Add-on to a version newer than 1.0.0.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13736

Affected Products

Wildapricotpress Add-On