PT-2026-79298 · Newpath · Wildapricotpress Add-On
CVE-2026-13736
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NewPath WildApricotPress Add-on versions prior to 1.0.1
Description
The NewPath WildApricotPress Add-on WordPress plugin fails to enforce privacy restrictions for members-only fields on an unauthenticated REST route. This allows anonymous visitors to access sensitive personally identifiable information (PII), specifically member email addresses and phone numbers, which are intended to be visible only to authenticated members.
Recommendations
Update the NewPath WildApricotPress Add-on to a version newer than 1.0.0.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wildapricotpress Add-On