๐Ÿ” CVE Alert

CVE-2026-13736

UNKNOWN 0.0

NewPath WildApricotPress Add-on โ€“ Member Directory <= 1.0.0 - Unauthenticated Member PII Disclosure via REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.

Vendor unknown
Product newpath wildapricotpress add-on
Published Aug 21, 2026
Stay Ahead of the Next One

Get instant alerts for unknown newpath wildapricotpress add-on

Be the first to know when new unknown vulnerabilities affecting unknown newpath wildapricotpress add-on are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / NewPath WildApricotPress Add-on
0 โ‰ค 1.0.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/97fe9780-ad69-4f36-9496-5ca9c0e2bc39/

Credits

Huynh Kien Minh WPScan