CVE-2026-13736

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route, allowing anonymous visitors to read member email addresses and phone numbers that are configured to be visible to members only.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-21 07:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-13736

Mitre link : CVE-2026-13736

CVE.ORG link : CVE-2026-13736


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control